Tuesday, June 1, 2021

Understanding Wi-Fi Speed and How 6 GHz Compares

TL;DR:

  • Wi-Fi 6E uses the same PHY standard, MIMO, and modulation rates from Wi-Fi 6. The only thing new is the 6 GHz spectrum.
  • 6 GHz can be faster, if you’re near an AP using wide channels.

- 2.4 Ghz and 5 GHz still have advantages, such as longer range, better wall penetration, and legacy compatibility.

Before we talk about the nature of 6 GHz Wi-Fi, it’s helpful to understand the components of Wi-Fi connections and how they interact to determine performance. Consumer routers claim numbers like 10,800 Mbps of throughput, but where does that number come from? Why are the numbers what they are, and why don’t I get 10,800 Mbps on my speed tests, dang it!?

Start with 10,800 Mbps

  • 2.4 GHz: 4x4, up to 1,200 Mbps with 40 MHz Channels
  • 5 GHz: 4x4, up to 4,800 Mbps with 160 MHz Channels
  • 6 GHz: 4x4, up to 4,800 Mbps with 160 MHz Channels

1,200 Mbps + 4,800 Mbps + 4,800 Mbps = 10,800 Mbps.

Go Down to One Band

Since Wi-Fi connections only happen on a single band, you’re only able to access one band at a time. If you use 5 GHz or 6 GHz, you’re down to 4,800 Mbps. This is using 160 MHz channels, and 4 spatial streams.

Limit MIMO to 2x2

MIMO (Multiple Input, Multiple Output) is a direct capacity multiplier, and it multiplies capacity using the same spectrum. While most high-end Wi-Fi 6 access points support 4x4:4 MIMO, the vast majority of client devices top out at 2 spatial streams. Battery operated Wi-Fi clients like your smartphone or laptop are almost all 2x2:2 devices. Going from 4 streams to 2 streams cuts our maximum link rate from 4,800 Mbps to 2,400 Mbps, if using a 160 MHz channel.

If Using 5 GHz, Set Channel Width to 80 MHz

Using 160 MHz channels in 5 GHz requires the use of DFS, and not all devices support DFS operation. 80 MHz channels are much more realistic option for 5 GHz, limiting maximum link rates to 1,200 Mbps. With Wi-Fi 6E, you get access to 6 or 7 more 160 MHz channels, and don’t need to use AFC or DFS if operating indoors. Range is less though, since 6 GHz attenuates faster, wider channels increase background interference, and 6 GHz indoor low-power AP transmit power is limited. For more details, see the Device Class and EIRP Limit section of Wi-Fi 6E's Current Status.

Set Modulation/Coding to 256-QAM or Lower

The maximum link rate requires 1024-QAM modulation, and a very high signal-to-noise ratio (SNR). The highest data rates are only possible in the best situations, with an AP nearby and limited interference on the channel. A more realistic modulation is 256-QAM or 64-QAM, resulting in a maximum link rate in the range of 600-900 Mbps for 80 MHz 2x2, or 1,200 to 1,800 Mbps for 160 MHz 2x2.

TCP/IP Overhead

Even in wired networks, there’s around a 5% overhead in TCP/IP connections. That 5% comes from all the data that’s required to setup the connection and address the packets and frames being exchanged. Jumbo frames can help a bit here, but come with their own issues. See Wikipedia for more details.

Beacons and Management Traffic

Beacon frames are how an AP advertises networks to client devices. In order to ensure that all devices in range are able to understand them, access points send out management traffic such as beacon frames at the lowest supported data rates. This expands the range of the broadcasts, but also acts as a speed bump, consuming precious airtime. The amount of management traffic increases with additional SSIDs, and features such as beamforming. You can limit the impact of management traffic by restricting minimum data rates. That’s usually only necessary in dense multi-AP networks, where small cell sizes and careful channel planning are important.

Half-Duplex

Wi-Fi is half-duplex, meaning on one device can be transmitting at a time, and only in one direction. To make an analogy, Wi-Fi is a walkie talkie, not a phone call. Ethernet is full-duplex, and allows transmissions in both directions at the same time. Wi-Fi does not. Wi-Fi being half-duplex doesn’t mean that throughput is cut in half, but it does mean that Wi-Fi devices can’t multi-task. When downloading a large file, a client device has to take many short breaks to transmit TCP acknowledgement frames back to it’s AP, or to allow others to transmit. Wi-Fi devices can’t download and upload data at the same time, or talk when others are talking.

Wi-Fi is a Shared Medium: Collisions and Re-transmissions

In addition to being half-duplex, Wi-Fi is a shared medium. When one device is transmitting on a channel, all other devices in range must wait their turn. If multiple devices transmit at the same time a collision can occur, causing the transmissions to be jumbled. When collisions occur, devices need to wait for a random length of time before re-transmitting. This can also cause link rates to be lowered temporarily, resulting in lower effective throughput for everyone.

PHY Link Rate is an Estimate, and an Average

When you see a link rate of 1200 Mbps, that doesn’t mean every single frame gets sent at 1024-QAM modulation. Individual frames may get sent above or below the current link rate values.

In Summary

  • A 2x2 device on an 80 MHz channel can achieve a maximum link rate of 1200 Mbps, resulting in throughput around 800-900 Mbps in ideal conditions.

  • A 2x2 device on a 160 MHz channel can achieve a maximum link rate of 2400 Mbps, resulting in throughput around 1400-1600 Mbps in ideal conditions.

This isn’t even all of the factors. If you’re interested in reading more, the CWNP blog has a great list of sources of overhead in Wi-Fi .

6 GHz Wi-Fi Characteristics

There’s nothing special added in 6 GHz to reduce latency, or increase speeds. Wi-Fi 6E uses the same PHY standard, MIMO, and modulation rates from Wi-Fi 6. The only thing new is the 6 GHz spectrum. An 80 MHz channel in 5 GHz is going to perform essentially the same as an 80 MHz channel in 6 GHz, with a few caveats:

  • Higher frequencies attenuate faster, so 6 GHz signals offer slightly less range than 5 GHz.
  • Indoor, low-power 6E devices like the RAXE500 are limited to a slightly lower EIRP (2) in the 6 GHz band compared to the 2.4 GHz and 5 GHz bands.
  • 6 GHz outdoor operation is more complicated, and regular-power outdoor APs require the use of the new AFC system, which is similar to DFS in 5 GHz. Standard-power APs will need to report their location before being able to operate at their full power.
  • Indoor, low-power devices don’t need to worry about AFC or DFS. Combined with a big chunk of new spectrum, this makes 80MHz and 160 MHz channels more practical to use.

Maximum allowed transmit power in 6E increases with channel width. You’ll get the same 30 dBm maximum EIRP allowed in 5 GHz, but only with a 320 MHz wide channel. 320 MHz channels should be supported in Wi-Fi 7 (802.11be), but for now 6 GHz indoor range will be less than the maximum possible with 5 GHz. - 160 MHz channels reduce maximum allowed EIRP by 3 dB - 80 MHz channels reduce maximum allowed EIRP by 6 dB - 40 MHz channels reduce maximum allowed EIRP by 9 dB - 20 MHz channels reduce maximum allowed EIRP by 12 dB

6 GHz offers more bandwidth and less interference. 6 GHz allows for up to seven 160 MHz channels or fourteen 80 MHz channels, making them much more usable in the real world. Because of this, 6 GHz can be faster, if you’re near an AP using wide channels. 2.4 Ghz and 5 GHz still have advantages, such as longer range, better wall penetration, and legacy compatibility.



Cisco's VIC, Adapter FEX, and Nexus 9K

Many years ago, I deployed Cisco C-Series servers in standalone mode to Nexus 5Ks via VICs, and I enabled Adapter-FEX (switchport mode vntag) in order to allow for deploying many vNICs to each server.

However, these days it seems that the Nexus 9K has no support for Adapter-FEX, or at least I can't find documentation for it. Does this mean we can no longer configure multiple vNICs on standalone servers with VICs? Or is there a more modern methodology for enabling vNICs this way? Any insights would be appreciated!



Network documentation tool to generate packet headers

Hi,

Please delete this is deemed inappropriate.

A few months ago I stumbled upon a website/tool that could generate images for use in documentation such as IP headers, tcp segments and frames, tcp flows among others.

I have searched for days and for the life of me I'm unable to find it.

It could generate images that look like this and this from the web browser.

I have already found http://www.luismg.com/protocol/ but this is only ascii.



Managed switch with a fibre connection - can i unplug without a restart?

Do managed switches such as the netgear gs110tp with a 1000base fibre module (SX/LC) need restarting or any config changes when you unplug the fibre cable (OM3 50-125) then replug it back in later? Probably overthinking and it just works like normal Cat5e switches but wanted to check? I need to borrow a fibre cable from a working switch to test on a potentially faulty setup elsewhere in the building.

I have experience within networking just not much on the fibre side of it and the person who deals with this is out for next couple of days.



How to secure RDP?

Hi Looking for a solution to secure a remote connection to my small office. I randomly need an outside person to connect to it remotely, and I have a dedicated pc on the network for this purpose, with Remote Desktop from MS. Running windows server and a small number of clients.

I see in the logs of our router a lot of brute force attacks on RDP. So would like to secure it better.

I am looking for an easy way to improve security.

Maybe something like the following?

  • A new firewall with a inbound VPN connection?

  • Software installed on the PC that use Google Authenticator?

Suggestions? I can’t afford costly equipment or big expenses on software… but surly a safe and easy solution is worth the money. Thank you.



Securing Dedicated Link communication?

Hello, i have problem figuring out proper and cheap solution to secure communication on Dedicated Link between two offices.

Infrastructure:

Main Router running pfSense. Eth0: WAN, eth 1-2 and local LANs (including intranet services that both offices need to access),

eth3 goes directly do ethernet port on my ISP device configured as an Transparent Dedicated Link to my other office.

In the other office I have ethernet port on ISP device that acts like it would be directly connected to my Eth3 port on my main router, so we have it connected to UniFi switch and there it branches down on workstations.

All of their traffic (including internet) goes through Dedicated Link and my main router.

Link speed is not an issue.

https://i.postimg.cc/L6xsN0ZC/2021-06-01-08-56-29-app-diagrams-net-4b743ac90764.png

Right now it acts as LAN network and is easy to manage, but if my ISP makes mistake, security of my Dedicated Line can be compromised.

I'm searching for a way to encrypt this communication without sacraficing the ease of management of the second office and i need to make it cheap :(

Do you guys have any ideas?



Monday, May 31, 2021

What could cause packet loss one-way

I'm relatively new to the field, and don't have much experience with enterprise equipment.

I'm a technician that works on RF equipment, so I don't have much experience with any sort of IP data structures, however there is some sort of communication issue between the Modem (which I set up) and our Level 3 switch (which I believe is Cisco, and was set up by the technicians in another department).

When we have the switch ping our modem, it reports a 10% packet loss, however when the modem pings the switch, they all go through fine. We've replaced Cat 6, SFP adapter, and plugged into a different SFP port on the switch. I'm sure the other shop has taken more troubleshooting steps, I just don't know what.

We haven't tried a different port on the Modem yet, as custom configuration is not particularly easy with it. We don't have any useful documentation on its CLI, it's GUI is confusing. All we know is that it runs some proprietary software in some Unix-like operating system (likely a Linux kernel). No one here knows anything about this equipment, so far I was the only person to get the modem-to-modem RF communication working. If anyone has used iDirect equipment, tips would be appreciated.



stable version of controller unifi

Hi guys.I am very happy to join you...

I want to use radius and hotspot service of unifi controller.

now when i enable hotspot service,it doesn't redirect web auth for authenticate Voucher based.

version controller:6.0.40

firmware access point:4.3.20.11298 AP AC LR

I just want to ask from someone who use unifi controller and radius and hotspot, which version of controller and firmware access point they use ?

Thank you.



How can I find out which devices use the Treck TCP/IP stack?

Hi there, I have recently come across a vulnerability in older versions of the treck tcp/ip stack (CVE-2020-11896) and wanted to test it out on my devices. I wanted to ask: is there a way I can find out which devices use the treck tcp/ip stack so I can try the exploit on them? I have an HP printer, and a few other IoT devices. Thanks for any help!



BGP issues on Fortigate

Currently I'm trying to advertise my /22 IP Blocks using BGP using Fortigate 600E (OS 6.4.4). I understand a router it best fitted to do BGP but due to current financial situation, we cannot buy a router.

I have a X.X.120.0/22 IP Block that I'm advertising to two independent provider. I am advertising X.X.120.0/23 and X.X.120.0/22 via ISP1 and I am advertising X.X.122.0/23 and X.X.120.0/22 via ISP2. Each provider is sending me a default route and their respective IP Blocks. Using Weight, I can chose which default route I want entered in the routing table.

I assign a static IP on laptop of X.X.120.2, Gateway .1. If I make the default route from ISP1 to go in the routing table, everything is ok. If make the default route of ISP2 to go in the routing table, I am unable to browse. DIG DNS (UDP), PING (ICMP), and traceroute work ok. I do notice that I can browse some google or youtube sites but this is because its served using UDP. With this, it seems that its affecting TCP traffic only.

I even tried adjusting the TCP MSS (1300 - 1430) but that didnt help.

If I turn off ISP1 link, everything works using ISP2 only. If I turn off ISP2 link, everything works using ISP1 only.

The reason I'm trying to advertise two /23 is for loadbalancing and to maximize the link usage since each link is not cheap.

Things I've tried: * enabled asymmetric routing * enabled tcp-session-without-syn in both in to out and out to in firewall rules. * enabled auxiliary-session * route look up matches the default route. * policy look up matches the in to out firewall rule. 

I have a support case opened with fortinet but even them seem to be lost and puzzled.