D-Link DWS-4026 [717/741] Mitigating a rogue client threat

D-Link DWS-4026 [717/741] Mitigating a rogue client threat
DetectingandPreventingWirelessIntrusion
D-Link UnifiedWiredandWirelessAccessSystem
November2011 Page717
DLinkUWSUserManual
MitigatingaRogueClientThreat
Inthisscenario,thenetworkadministratorforaretailstoreisimpleme ntingRogueClientThreatMitigationto
provideadditionalsecurityinherstorelocatedinashoppingmall.SeveraltabletPCsareusedtotrack
inventorywithintheestablishment.ThenetworkadministratordecidestouseClie ntThreatMitigationtomake
suretha
tthesetabletsareassociatedonlywithcompanycontrolledAPs.
ThisscenariousesClientThreatMitigationratherthantheAPDeAuthenticationAttackforthefollowing
reasons:
•UsingAPMitigationwouldbedifficultbecausetheadministratorhasnocontroloverAPsinadjoining
stores,andkeepingupwithchangesinAPsloc
atedinotherstoresmightcreatetoomuchoverhead.
•Iftheadministratorweretoaccidentallyclassifyaneighboringstore'sAPasRogueandjamtheother
store'straffic,shecouldpotentiallybeliableforinterruptingthebusinessoftheadjacentstore.
•EmployeescanbepreventedfromusingthetabletPCstoaccesspubl
icnetworksfornonwork related
functionsortocircumventcorporatefirewalls,whichcouldexposecompanydata.
ToaddthetheclientsthatareallowedtoaccessthenetworkintotheKnownClientDatabaseandconfigurethe
ClientThreatMitigationfeature:
1. VerifytheMACAuthenticationmodeiswhitelistontheWLAN>Adminis
tration>AdvancedConfiguration
>Globalpage.
ThewhitelistauthenticationmodemeansthatwirelessclientswithMACaddressesthatarespecifiedin
theKnownClientdatabase,andarenotexplicitlydeniedaccess,aregrantedaccess.IftheMACaddressis
notinthedatabasethentheaccesstothenetworkisden
ied.
Note:RadiosinnonsentrymodewillnottransmitClientThreatMitigationframes.Therefore,sentry
radiosmustbedeployedforthenetworkadministratortousethisfeature.

Содержание

Похожие устройства

Скачать