On a cabled network the medium is yours and nobody sees it. On a wireless network everything changes: the medium is public, anybody in the car park can listen, two hosts may be unable to hear each other although both are talking to the same access point, and collisions cannot be detected - not even in principle. Each of these problems demanded a solution of its own, and this lecture takes them in turn, from the physics of waves to the protocol that decides who may speak, and to the encryption that keeps the car park out.
1From the layer 2 lecture4 min
- On a shared medium, two hosts transmitting at the same time produce a collision.
- CSMA/CD solved that: listen, transmit, and if you detect a collision, stop and try again after a random interval.
- A collision domain is the area in which two transmissions can crash into each other.
- The MAC address identifies an interface; the frame has a source, a destination and a CRC.
- Modulation turns bits into a signal transmissible over the medium (lecture 1).
Today we shall see that CSMA/CD, the mechanism that made Ethernet possible, cannot be used in the air. Not because somebody decided otherwise, but because physics does not allow it. And from that impossibility follows almost everything that is peculiar to 802.11.
Learning outcomes
- Explain the trade-off between frequency, coverage and throughput
- Say what raised the throughput from 2 Mbps to over 10 Gbps, through four levers
- Distinguish FHSS, DSSS, OFDM and OFDMA
- Plan the channels in a building with several access points
- Use the terms BSS, IBSS, ESS, SSID and BSSID correctly
- Explain why CSMA/CD does not work in the air and how CSMA/CA replaces it
- Describe the hidden node problem and how RTS/CTS solves it
- Choose the right security mechanism and say why the "simple" ones are not security
2The physics behind the decisions9 min
Wireless networks use microwaves, a slice of the electromagnetic spectrum lying roughly between 1 and 10 GHz. The choice is not arbitrary: it follows from a trade-off with five terms, worth keeping in mind every time somebody proposes "a better band".
| Property | Low frequencies | High frequencies |
|---|---|---|
| Propagation distance | large | small |
| Penetration of walls | good | poor |
| Interference | plenty - the band is crowded | little |
| Bandwidth available | small | large |
| Cost of equipment | low | high |
Wavelength is inversely proportional to frequency. At 2.4 GHz it is roughly 12.5 cm; at 5 GHz, roughly 6 cm.
A wave "goes round" obstacles smaller than its wavelength more easily and is absorbed or reflected by those comparable to it or larger. A 15 cm wall is, for a 12.5 cm wave, an obstacle it can still negotiate; for the 6 cm wave it is a wall in the full sense of the word.
The same reason explains why FM radio works in a tunnel and Wi-Fi does not: at 100 MHz the wavelength is three metres.
Compare 2.4 and 5 GHz at the same distance: the loss grows by about 6.4 dB from the change of frequency alone, with no extra wall. This is, in figures, the explanation for why the 5 GHz band "does not reach as far" - although the transmitted power is identical. And the calculation above is for free space: in a real building you must add 3–5 dB per plasterboard wall and 10–15 dB per concrete one.
3The free bands and who else uses them6 min
| Technology | Band | Application |
|---|---|---|
| LoRaWAN | 868 MHz (EU) | long-range IoT, very low power, tiny throughput |
| Zigbee | 868 MHz and 2.4 GHz | automation, sensors, smart bulbs |
| Bluetooth | 2.4000 – 2.4835 GHz | peripherals, short distances |
| Wi-Fi | 2.4 / 5 / 6 GHz | wireless local networks |
| The microwave oven | 2.45 GHz | it communicates nothing, but transmits hundreds of watts |
All of these work in the ISM bands (Industrial, Scientific and Medical), usable without a licence and without a fee, subject to certain power limits. In Romania the allocations are regulated by ANCOM.
There is no administrator of the band. There is nobody to complain to. The only remedy is to move to 5 or 6 GHz, where there are fewer people - for now.
4The evolution of the 802.11 standards9 min
| Generation | Standard | Band | Maximum rate | Modulation / access | Year |
|---|---|---|---|---|---|
| Wi-Fi 0 | 802.11 | 2.4 GHz | 2 Mbps | FHSS / DSSS | 1997 |
| Wi-Fi 1 | 802.11b | 2.4 GHz | 11 Mbps | DSSS | 1999 |
| Wi-Fi 2 | 802.11a | 5 GHz | 54 Mbps | OFDM | 1999 |
| Wi-Fi 3 | 802.11g | 2.4 GHz | 54 Mbps | OFDM / DSSS | 2003 |
| Wi-Fi 4 | 802.11n | 2.4 / 5 GHz | 600 Mbps | OFDM + MIMO | 2009 |
| Wi-Fi 5 | 802.11ac | 5 GHz | 6.93 Gbps | OFDM, up to 8 streams | 2014 |
| Wi-Fi 6 | 802.11ax | 2.4 / 5 GHz | 9.6 Gbps | OFDMA | 2019 |
| Wi-Fi 7 | 802.11be | 2.4 / 5 / 6 GHz | ~30 Gbps | OFDMA, 4096-QAM | 2024 |
The growth from 2 Mbps to 30 Gbps in less than three decades comes not from a single invention but from four levers pulled at once - all of them already known from lecture 1.
- Ever denser modulations. From BPSK and QPSK to 256-QAM (802.11ac) and 4096-QAM (802.11be). Each step raises the number of bits per symbol - and demands, in return, a better signal-to-noise ratio. That is why the maximum rate is obtained only beside the access point.
- MIMO. Several antennas transmitting independent spatial streams at once. Four streams means, in good conditions, four times the throughput - using exactly the same band.
- Wider channels. From 20 MHz to 40 MHz (802.11n), 160 MHz (802.11ac) and 320 MHz (802.11be). Twice the band means twice the throughput - if you can find that much clean spectrum.
- Better multiple-access methods. The move from DSSS to OFDM and then to OFDMA.
- half the throughput to the protocol's headers and acknowledgements (the medium is half-duplex, every frame requires an ACK);
- another part to sharing with the other hosts in the same BSS;
- another part to the modulation stepping down with distance.
A "1200 Mbps Wi-Fi 6" realistically delivers 400–600 Mbps at a few metres and far less in the next room.
5Spreading and multiple access10 min
It looks wasteful: if the information fits in 1 MHz, why occupy 20?
Because in a free band the noise is localised and unpredictable: the microwave oven ruins one slice, the Bluetooth phone another. A signal concentrated in 1 MHz that happens to land on the noise is lost completely.
A spread signal over 20 MHz loses only the affected slice, and the rest is enough for the receiver to reconstruct the information. In addition, with the energy distributed, the signal is harder to detect for somebody who does not know what to look for - which is why the technique comes, like much else, from military applications.
| Technique | How it works | Note |
|---|---|---|
| FHSS Frequency Hopping | the transmitter "hops" between sub-bands according to a sequence known to both ends | simple, but it uses one sub-band at a time; Bluetooth still uses it |
| DSSS Direct Sequence | each bit is replaced by a fixed sequence of chips, which occupies the whole channel | the signal is recovered even if part of the sequence is disturbed |
| OFDM | the band is divided into many orthogonal subcarriers, transmitted at once | very resistant to multipath reflections; the basis of every modern standard |
| OFDMA | the subcarriers are allocated to different users, simultaneously | Wi-Fi 6; it turns a contention medium into a scheduled one |
OFDMA loads into the same lorry parcels for several recipients and drops them off in turn, along the same road. Nobody waits for a whole lorry for one envelope.
That is why Wi-Fi 6 is not much faster for a single client but is dramatically better in a room with a hundred laptops - exactly the scenario of a lecture hall.
OFDM = several subcarriers, for a single user at a time.
OFDMA = the same subcarriers, divided between several users.
They combine: a Wi-Fi 6 AP does all three at once.
6Channel planning9 min
The 2.4 GHz band has roughly 85 MHz usable (2400 – 2485 MHz), and an 802.11g channel occupies about 22 MHz. The channels, however, are defined every 5 MHz - so they overlap massively. The result is room for exactly three networks that do not overlap at all: channels 1, 6 and 11.
Put all three access points on channels 1, 6 and 11 - no overlap at all. Then move one to channel 3 and see what happens: it partially overlaps both 1 and 6. It has damaged two networks instead of avoiding one.
And partial overlap is worse than using the same channel. Two networks on channel 1 hear each other and share the medium politely through CSMA/CA: each waits while the other speaks. A network on channel 3 is not heard as a valid signal, so nobody yields the medium to it - to the others, it is noise.
Beware, however, of the DFS channels (52–140): there Wi-Fi is a guest and the weather radars are the owner. If the equipment detects a radar, it is obliged to leave the channel at once - which means a few seconds of interruption for every client.
7The organisation of a wireless network9 min
| Term | What it is |
|---|---|
| BSS - Basic Service Set | the basic unit: one or more hosts plus at most one access point |
| IBSS - Independent BSS | a BSS with no access point: an ad-hoc network, the hosts talk directly to one another |
| ESS - Extended Service Set | several BSSs joined by a distribution system (usually the cabled network) |
| BSSID | a 48-bit identifier of a BSS; in a network with an AP it is the MAC address of the access point |
| SSID | the name of the network, configurable by the administrator; what the user sees in the list |
The typical equipment is: wireless adapters, access points, wireless bridges (joining two cabled segments through the air), signal repeaters, directional or omnidirectional antennas and, in large installations, WLAN controllers that centrally manage dozens of lightweight access points - the latter having practically no configuration of their own.
8Medium access11 min
The wireless medium is shared, exactly like the old coaxial cable. But CSMA/CD cannot be used, for two physical reasons that cannot be got round:
Reason 1. A host cannot listen while it transmits. Its own signal, at its own antenna, is tens of orders of magnitude stronger than anything it could receive from a distance. It is like trying to hear a whisper in the next room while shouting.
Reason 2. Even if it could, the collision happens at the receiver, not at the transmitter. Two hosts 100 m apart may transmit without disturbing each other at all - but their signals can collide perfectly well at the access point between them.
On cable both problems disappear: the signal is the same along the whole wire, and a host can compare what it transmits with what is heard on the medium.
The solution is CSMA/CA - Collision Avoidance instead of Detection. If we cannot detect collisions, we prevent them.
| Function | When it is used | The medium access decision |
|---|---|---|
| DCF - Distributed Coordination Function | always, ad-hoc networks included | distributed, through CSMA/CA: every host listens, waits DIFS and a random backoff |
| PCF - Point Coordination Function | optional, only with an access point | centralised: the AP polls the hosts in turn, during a contention-free period |
9The 802.11 frame8 min
In the air a frame has four potentially different roles: who transmits it now, who receives it now, whom the original came from, and whom it is ultimately for. In an ordinary BSS three are enough, because the AP is always one of the ends. The fourth appears only when the frame hops between two access points.
10Two problems that do not exist on cable10 min
The hidden node
The exposed node
The symmetrical problem, and rather less well known: a host hears a transmission and stays silent, although its own transmission would disturb nobody - because the recipients are in opposite directions.
The result is not a collision but a loss of capacity: the medium sits idle although it could have been used. The remedies are the use of different channels, directional antennas, or centralised coordination - which is exactly what OFDMA does in Wi-Fi 6.
The exposed node: I hear somebody I ought to disregard → I stay silent when I could speak → wasted capacity.
The first produces errors, the second slowness. The first has a standard solution (RTS/CTS), the second does not.
11The security of wireless networks12 min
On cable, an attacker has to get inside the building. In the air, being in the car park is enough. That difference explains why wireless security was, from the start, a harder problem - and why the first solutions failed spectacularly.
The mechanisms that are not security
| Measure | What it claims | Why it is not enough |
|---|---|---|
| Reducing the transmit power | the signal does not leave the building | a directional antenna picks it up from hundreds of metres away; and reception is far more sensitive than transmission |
| Hiding the SSID | the network becomes invisible | the SSID appears in the clear in the association frames of legitimate clients - you need only wait for one |
| Filtering by MAC address | only known devices get in | MAC addresses travel unprotected in every frame and can be copied within seconds |
The result: your telephone calls out the name of the "hidden" network in every café, airport and underground station you pass through. You have hidden the network where it lives and announced it everywhere else.
All three are useful as measures of hygiene - they reduce the noise and the opportunistic attempts - but none of them stops an attacker who knows what they are doing. Real security begins with encryption.
| Mechanism | Encryption | Authentication | Status |
|---|---|---|---|
| Open | none | none | only for public networks, with a portal |
| WEP (1999) | RC4, static key | shared key | completely broken; cracked in minutes |
| WPA (2003) | TKIP | PSK or RADIUS | a transitional solution, superseded |
| WPA2 (2004) | AES-CCMP | PSK or 802.1X | still acceptable |
| WPA3 (2018) | AES, protected management frames (PMF) | SAE instead of PSK | recommended |
WEP used RC4 with a fixed key, to which it added an initialisation vector (IV) of only 24 bits, transmitted in the clear, so that each frame would be encrypted differently.
24 bits means 16.7 million values. On a busy network they are exhausted within a few hours - and from the first repeated IV, information about the key can be deduced.
Worse: the attacker need not wait. They can inject traffic (replaying captured ARP requests) to force the network to generate IVs quickly. Since 2007, a WEP network is cracked in under five minutes, with public tools.
The general lesson: it was not the encryption that was weak but the way it was used.
Two improvements in WPA3 are worth understanding, because they solve concrete weaknesses of WPA2:
- SAE (Simultaneous Authentication of Equals) replaces the classic PSK. With WPA2-PSK, an attacker who captures the four-way handshake can try offline, endlessly and without touching the network, whole dictionaries. With SAE, every password attempt requires an interaction with the network - so the attack becomes slow, detectable and limitable.
- Perfect Forward Secrecy. The session key is derived afresh at every connection, so compromising the password does not allow previously recorded traffic to be decrypted. With WPA2, whoever had the password and an old capture could read everything.
For any organisational network - a faculty's included - enterprise is the only manageable option: you revoke a single account rather than changing a password for three thousand people.
The defence lies not in the password but in mutual authentication - the client must verify the certificate of the RADIUS server, exactly as a browser verifies the certificate of an HTTPS site. A device configured not to validate the certificate is vulnerable however strong the encryption.
12Common mistakes4 min
- "I put all the APs on free channels, 1, 3, 5" Channels 3 and 5 partially overlap 1 and 6, so they interfere with everything. Only 1, 6 and 11 in the 2.4 GHz band. No exceptions.
- "I hid the SSID, so the network is safer" It is not. And the clients call out the name of the network all over the world. A visible SSID, WPA3 or WPA2 with a long password. Security comes from encryption.
- "I set 40 MHz channels on 2.4 GHz, to get twice the throughput" A 40 MHz channel occupies nearly half the band and ruins both neighbours. 20 MHz on 2.4 GHz. Wide channels make sense only on 5 and 6 GHz.
- "The real throughput is far below the one on the box" That is normal: half the medium time goes on the protocol, the ACKs and sharing. Expect 40–50% of the theoretical figure, at best.
- "I added a repeater to cover the whole house" A repeater retransmits what it hears on the same channel, so it halves the available throughput and occupies the medium twice for every frame. A second AP connected by cable, on another channel. Or mesh with a dedicated radio.
- "MAC filtering keeps intruders out" The addresses travel in the clear in every frame and can be cloned within seconds. Useful as an inventory, useless as security.
- "I configured WPA2-Enterprise, but the clients do not check the certificate" An evil twin can capture anybody's credentials. Explicitly configure validation of the RADIUS server certificate on every device.
13Summary and glossary4 min
- Higher frequency = higher throughput, but less coverage and less penetration. There is no "better" band.
- Throughput grew through dense modulation, MIMO, wide channels and OFDMA.
- In the 2.4 GHz band there are exactly three non-overlapping channels: 1, 6, 11.
- SSID = the name of the network; BSSID = the MAC address of an AP. Roaming keeps the first and changes the second.
- CSMA/CD is impossible in the air: you cannot listen while transmitting, and the collision happens at the receiver.
- CSMA/CA: listen, DIFS, random backoff, transmit, wait for the ACK.
- The Duration field and the NAV are the "virtual" carrier sensing of the medium.
- RTS/CTS solves the hidden node, because the AP CTS is heard by everybody.
- Reduced power, a hidden SSID and MAC filtering are not security.
- WPA3 with SAE is the recommendation; Enterprise is the only manageable option in an organisation.
14Self-check questions6 min
15Further reading2 min
The last lecture brings together the attacks that work inside the local network - including those that exploit the very mechanisms studied in lectures 3 and 4, from the CAM table to the STP protocol - and the configurations that stop them.
Laboratory 7 includes building and securing a wireless network in Packet Tracer, with channel planning and WPA2-Enterprise.
- IEEE 802.11 - the complete standard, with the a/b/g/n/ac/ax/be amendments
- IEEE 802.11i - the security mechanisms that became WPA2
- Wi-Fi Alliance - the WPA3 specifications and the certification requirements
- ANCOM - the regulations for the ISM bands in Romania
- Matthew Gast, 802.11 Wireless Networks: The Definitive Guide