Containment Methods - Aruba IAP-335 User Manual

Instant software
Hide thumbs Also See for IAP-335:
Table of Contents

Advertisement

Containment Methods

You can enable wired and wireless containments to prevent unauthorized stations from connecting to your
Instant network.
Instant supports the following types of containment mechanisms:
Wired containment—When enabled, IAPs generate ARP packets on the wired network to contain wireless
l
attacks.
wired-containment-ap-adj-mac—Enables a wired containment to Rogue IAPs whose wired interface MAC
n
address is offset by one from its BSSID.
wired-containment-susp-l3-rogue—Enables the users to identify and contain an IAP with a preset MAC
n
address that is different from the BSSID of the IAP, if the MAC address that the IAP provides is offset by
one character from its wired MAC address.
Enable the wired-containment-susp-l3-rogue parameter only when a specific containment is required, to
avoid a false alarm.
Wireless containment—When enabled, the system attempts to disconnect all clients that are connected or
l
attempting to connect to the identified Access Point.
None—Disables all the containment mechanisms.
n
Deauthenticate only—With deauthentication containment, the Access Point or client is contained by
n
disrupting the client association on the wireless interface.
Tarpit containment—With Tarpit containment, the Access Point is contained by luring clients that are
n
attempting to associate with it to a tarpit. The tarpit can be on the same channel or a different channel
as the Access Point being contained.
Figure 98 Containment Methods
332
| Intrusion Detection
Aruba Instant 6.5.0.0-4.3.0.0 | User Guide

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents