D-Link DWS-4026 [709/741] Detecting and preventing wireless intrusion

D-Link DWS-4026 [709/741] Detecting and preventing wireless intrusion
DetectingandPreventingWirelessIntrusion
D-Link UnifiedWiredandWirelessAccessSystem
November2011 Page709
DLinkUWSUserManual
DetectingandPreventingWirelessIntrusion
ThissectiondescribeshowtouseofsomeoftheWirelessIntrusionDetectionSystem(WIDS)andWireless
IntrusionPreventionSystem(WIPS)functionsontheDLinkUnifiedWirelessSwitch.
Inthisexample,acompanyhasconfiguredawirelessnetworkwiththeVAPsshowninTable387.
ForinformationaboutconfiguringtheVAPssee“C
onfiguringaNetworktoUseWPA2EnterpriseandDynamic
VLANs”onpage689.
Asanadditionalsecuritymeasure,thenetworkadministratorhasdecidedtoemploytheuseoftheWIDS/WIPS
functionalitytofurtherprotectthecorporatenetwork.Theexamplesinthissectionshowhowtoconfigurethe
UnifiedSwitchandhowtomo
nitorthesystemasitmitigatespotentialsecurityrisksinthewirelessdomain.
ConfiguringaRadioinSentryMode
Toimplementthesecuritypoliciesofthecompanyinthisexample,thesecondradioontheAccessPoint
DWL8600isconfiguredinsentrymodetoscanforviolationsoftheWIDStests.Alternately,sep arateAPscan
beconfiguredasdedicatedsentryAPs.Whenaradiooperatesinsentrymode,thera
dioperformsacontinuous
radioscan.Insentrymode,nobeaconsaresent,andnoclientsareallowedtoassociatewiththeAPthrough
thesentryradio.
IfadedicatedsentryradioorAPisnotconfigured,theactiveradiosstillscanotherchannelsbutwilldosoata
slowerra
tethanaradioinsentrymode.TherateatwhicharadioscanstheRFtrafficisimportanttoWLAN
securitybecauseslowerscanningallowsRogueAPstoremainundetecte dforalongerperiodoftime.
Toenablesentrymodeinthedefaultprofileonradio1:
1. ClickWLAN>Adminis
tration>BasicSetup>RadiotoaccesstheWirelessDefaultRadioConfiguration
page.
2. SelectRadio1.
3. SelecttheRFScanSentryoption.
Table387:WIDS/WIPSVAPSummary
Network(SSID) VLAN Security Redirect
Visitor 10 None http://www.dlink.com/tw
Corporate 20 WPAEnterprise None
Note:Bydefault,thesentryradioscans802.11aand802.11g/bchannels.Toconfigurethesentry
radiotoscanonly802.11aor802.11b/gchannels,butnotboth,clickWLAN>Administration>
AdvancedConfiguration>APProfiles>ProfileName>RadiotoaccesstheAccessPointProfileRadio
Configurationpagefo
rtheselectedprofile.

Содержание

Похожие устройства

Скачать