Detecting And Preventing Wireless Intrusion; Configuring A Radio In Sentry Mode; Table 390: Wids/Wips Vap Summary - D-Link DWL-8600AP User Manual

Dws-4000 series access points
Hide thumbs Also See for DWL-8600AP:
Table of Contents

Advertisement

D-Link UWS User Manual

Detecting and Preventing Wireless Intrusion

This section describes how to use of some of the Wireless Intrusion Detection System (WIDS) and Wireless
Intrusion Prevention System (WIPS) functions on the D-Link Unified Wireless Switch.
In this example, a company has configured a wireless network with the VAPs shown in
Network (SSID)
Visitor
Corporate
For information about configuring the VAPs see
VLANs" on page
706.
As an additional security measure, the network administrator has decided to employ the use of the WIDS/
WIPS functionality to further protect the corporate network. The examples in this section show how to
configure the Unified Switch and how to monitor the system as it mitigates potential security risks in the
wireless domain.

Configuring a Radio in Sentry Mode

To implement the security policies of the company in this example, the second radio on the Access Point
DWL-8600 is configured in sentry mode to scan for violations of the WIDS tests. Alternately, separate APs can
be configured as dedicated sentry APs. When a radio operates in sentry mode, the radio performs a
continuous radio scan. In sentry mode, no beacons are sent, and no clients are allowed to associate with the
AP through the sentry radio.
If a dedicated sentry radio or AP is not configured, the active radios still scan other channels but will do so at
a slower rate than a radio in sentry mode. The rate at which a radio scans the RF traffic is important to WLAN
security because slower scanning allows Rogue APs to remain undetected for a longer period of time.
To enable sentry mode in the default profile on radio 1:
1. Click WLAN > Administration > Basic Setup > Radio to access the Wireless Default Radio Configuration
page.
2. Select Radio 1.
3. Select the RF Scan Sentry option.
Note: By default, the sentry radio scans 802.11a and 802.11 g/b channels. To configure the sentry
radio to scan only 802.11a or 802.11b/g channels, but not both, click WLAN > Administration >
Advanced Configuration > AP Profiles > Profile Name > Radio to access the Access Point Profile Radio
Configuration page for the selected profile.
D-Link
Oct. 2015

Table 390: WIDS/WIPS VAP Summary

VLAN
Security
10
None
20
WPA Enterprise
"Configuring a Network to Use WPA2-Enterprise and Dynamic
Detecting and Preventing Wireless Intrusion
Table
Redirect
http://www.dlink.com/tw
None
Unified Wired and Wireless Access System
390.
Page 726

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents