Rf Management; Rf Intrusion Detection/Rf Containment; Deploying Bsaps On The Same Layer-2 Subnet As The Bsc - ADTRAN BlueSecure Controller Setup And Administration Manual

Software release version: 6.5
Table of Contents

Advertisement

Note: Connect only the recommended number of BSAPs to a BSC:

RF Management

To overcome the various sources of RF noise and interference, and user loads that can
impede the performance of access points on your WLAN, the BSC incorporates
"DynamicRF™" functionality for use with BlueSecure Access Points.
Using its Dynamic RF functionality, the BSC adjusts the radio channel and power settings
of BSAPs under its control, whenever the BSC detects any non-optimal environmental
conditions such as:
general interference or noise
co-channel interference introduced by a neighboring AP
loss of connectivity to a BSAP
poor wireless client characteristics (low RSSIs, multiple failures or retries, etc.)
high user load
You can enable the Dynamic RF functionality on a global basis for all BlueSecure Access
Points connected to a BSC or selectively enable Dynamic RF on a per-BSAP basis.

RF Intrusion Detection/RF Containment

The BSC detects and protects against rogue devices, ad-hoc networks, and a large
number of WLAN Denial of Service (DoS) and spoofing attacks.
The BSC provides RF intrusion detection by analyzing the data collected from its BSAPs
operating in sensor-only mode to detect attacks, vulnerabilities, and rogue devices in the
RF space.
Should a rogue AP or client be discovered, the BSC configures the BSAP nearest the
rogue device to initiate containment using 802.11 de-authentication and/or
disassociation messages. Up to five BSAPs can participate in the containment if range
permits. The BSAPs participating in the RF containment remain online for wireless access
during the containment period.
All RF IDS alarms issued by a BSAP automatically generate a corresponding SNMP trap
message and syslog message.

Deploying BSAPs on the Same Layer-2 Subnet as the BSC

The deployment prerequisites for BSAPs are:
BSAP IP Address - Each BSAP requires a unique IP address.
Host BlueSecure Controller IP Address - Each BSAP requires the IP address of the
home BSC to which it will connect and obtain its software image and configuration.
If the BSAPs are on the same subnet as the home BlueSecure Controller as shown in
Figure 12-2, you can run a DHCP server on the BSC to manage IP address assignment to
BSAPs. In this scenario, the BSC must be the only DHCP server for the subnet.
Alternatively, you can configure the BlueSecure Controller to run a DHCP relay agent to
relay DHCP communications between the BSAPs and a DHCP server on your network.
When you run a DHCP server or a DHCP relay agent on the BSC to assign IP addresses
to BSAPs on the managed side, the BSC will also pass its IP address to the BSAPs
automatically using vendor-specific option 43. In this way, the BSAPs will learn the home
BSC to which they should connect.
BlueSecure™ Controller Setup and Administration Guide
Deploying BSAPs on the Same Layer-2 Subnet as the BSC
12-3

Advertisement

Table of Contents
loading

Table of Contents