CTS 251 – Fast BSS Transition Frame Exchanges (CWAP)




Clear To Send: Wireless Network Engineering show

Summary: <br> In this episode, we’re going to cover a small topic of the CWAP certification. We’re taking a look at the frame exchanges that occur during 802.11r or Fast BSS Transition. <br> <br> <br> <br> In our scenario we’ll use my iPhone which associates to AP1 and roams to AP2. <br> <br> <br> <br> <br> <br> <br> <br> <br> <br> Without 802.11r, the roam will take additional time to complete. 802.11r enables that roam to complete in less time. <br> <br> <br> <br> There are two methods Fast Transition will use when a device is moving from its current AP to another AP:<br> <br> <br> <br> * Over-the-Air (OTA)* Over-the-DS (OTDS) (distribution system)<br> <br> <br> <br> In OTA, a device roaming to another AP will communicate with that target AP directly during the roaming process. <br> <br> <br> <br> In OTDS, the device roaming to another AP will initiate the process with Action frames sent through its current AP destined to the target AP. Then the roaming process is finalized with direct communication with the target AP.<br> <br> <br> <br> Over-the-Air<br> <br> <br> <br> Let’s take a look at the messages being used by a device to its target AP. There are four frame exchanges to look at:<br> <br> <br> <br> * Message 1 – Authentication Request from the device (originator) to the target AP* Message 2 – Authentication Response from the target AP destined to the originator* Message 3 – Reassociation Request frame from the device to the target AP* Message 4 – Reassociation Response frame from the target AP to the originator<br> <br> <br> <br> Let’s take a look at the full frame exchange process<br> <br> <br> <br> <a href="https://www.cleartosend.net/wp-content/uploads/2021/01/image-1.png"></a><br> <br> <br> <br> Within the Beacon, Probe Response, Authentication, and Reassociation frames you will find the Mobility Domain information element. Access points part of the same ESS will contain the same Mobility Domain Identifier. There will also be a Fast BSS Transition over DS element which will indicate whether this frame is OTA or OTDS.<br> <br> <br> <br> <a href="https://www.cleartosend.net/wp-content/uploads/2021/01/image-3.png"></a><br> <br> <br> <br> <br> <br> <br> <br> Over-the-DS<br> <br> <br> <br> Let’s take a look at the messages being used by a device to its target AP. There are four frame exchanges to take note of:<br> <br> <br> <br> * Message 1 – Fast Transition Request Action frame originating from the device (originator) to the current AP with the target AP’s BSSID in the Address field of the frame* Message 2 – Target AP sends a Fast Transition Response frame to the originator* Message 3 – Originator sends a Reassociation frame destined to target AP* Message 4 – Reassociation Response frame from the target AP to the originator<br> <br> <br> <br> Let’s take a look at the full frame exchange process<br> <br> <br> <br> <a href="https://www.cleartosend.net/wp-content/uploads/2021/01/image-4.png"></a><br> <br> <br> <br> <br> <br> <br> <br> Wireshark filter to find Over-the-Air or Over-the-DS Fast BSS Transition frames and which mode they are in:<br> <br> <br> <br> wlan.mobility_domain.ft_capab.ft_over_ds<br> <br> <br> <br> Links and Resources<br> <br> <br> <br> * <a href="https://www.cleartosend.net/fast-bss-transition-802-11r/" target="_blank" rel="noreferrer noopener">Episode 198</a>* <a href="https://drive.google.com/drive/folders/1Ekfh6EZA0Fh-F9Be6S58CRX8WL-4nJue?usp=sharing" target="_blank" rel="noreferrer noopener">PCAP Files</a>* <a href="https://cleartosend.net/survey" target="_blank" rel="noreferrer noopener">Listener Survey</a><br>