Countermeasures; Summary Of Rogue Detection Features - D-Link DWS-1008 - AirPremier MobileLAN Switch Product Manual

8 port 10/100 wireless switch with power over ethernet
Hide thumbs Also See for DWS-1008 - AirPremier MobileLAN Switch:
Table of Contents

Advertisement

You can enable MSS to use countermeasures against rogues. Countermeasures consist of packets
that interfere with a client's ability to use the rogue. Countermeasures are disabled by default. You can
enable them on an individual radio-profile basis. When you enable them, all devices of interest that are
not in the known devices list become viable targets for countermeasures.
Countermeasures can be enabled against all rogue and interfering devices, against rogue devices only,
or against devices explicitly configured in the switch's attack list.

Summary of Rogue Detection Features

The table below lists the rogue detection features in MSS.
Rogue Detection
Feature
Classification
Permitted vendor list
Permitted SSID list
Client black list
Attack list
Ignore list

Countermeasures

Active scan
D-Link AP signature
Log messages and
traps
D-Link DWS-1008 User Manual
Countermeasures
Description
MSS can classify third-party APs as rogues or
interfering devices. A rogue is a third-party AP whose
MAC address MSS knows from the wired side of the
network. An interfering device does not have a MAC
address known on the wired side. MSS can detect rogue
clients, locate their APs, and issue countermeasures
against the APs.
List of OUIs to allow on the network. An OUI is the first
three octets of a MAC address and uniquely identifies
an AP's or client's vendor.
List of SSIDs allowed on the network. MSS can issue
countermeasures against third-party APs sending
traffic for an SSID that is not on the list.
List of client or AP MAC addresses that are not allowed
on the wireless network. MSS drops all packets from
these clients or APs.
List of AP MAC addresses to attack. MSS can issue
countermeasures against these APs whenever they
are detected on the network.
List of MAC addresses to ignore during RF detection.
MSS does not classify devices on this list as rogues or
interfering devices, and does not issue countermeasures
against them.
Packets sent by D-Link APs to interfere with the operation
of a rogue or interfering device. Countermeasures are
configurable on a radio-profile basis.
Active scan sends probe any requests (probes with a
null SSID name) to look for rogue APs.
Active scan is configurable on a radio-profile basis.
Value in an AP's management frames that identifies
the AP to MSS. AP signatures help prevent spoofing of
the AP MAC address.
Messages and traps for rogue activity.
Applies To
Third-Party APs
Yes
Yes
Yes
Yes
Yes
Yes
Yes
Yes
No
Yes
Clients
Yes
No
Yes
Yes
No
Yes
Yes
No
No
Yes
80

Advertisement

Table of Contents
loading

Table of Contents