Using Rapids And Rogue Classification; Introduction To Rapids - Dell PowerConnect W-Airwave User Manual

W-airwave 7.3 user guide
Hide thumbs Also See for PowerConnect W-Airwave:
Table of Contents

Advertisement

This chapter provides an overview to rogue device and IDS event detection, alerting, and analysis using RAPIDS
in AirWave, and contains the following sections:
"Introduction to RAPIDS" on page 163
"Viewing Rogues on the RAPIDS > List Page" on page 172
"Setting Up RAPIDS" on page 165
"Defining RAPIDS Rules" on page 168
"Score Override" on page 176
"Using the Audit Log" on page 177
"Additional Resources" on page 178

Introduction to RAPIDS

Rogue device detection is a core component of wireless security. With the RAPIDS rules engine and containment
options, you can create a detailed definition of what constitutes a rogue device, and quickly act on a rogue AP for
investigation, restrictive action, or both. Once rogue devices are discovered, RAPIDS alerts your security team of
the possible threat and provides essential information needed to locate and manage the threat.
RAPIDS discovers unauthorized devices in your WLAN network in the following ways:
Over the Air
Using your existing enterprise APs
Optional AirWave Management Client (AMC)
On the Wire
Polling routers and switches to identify, classify, and locate unknown APs
Using HTTP and SNMP scanning
NOTE: To set up a scan, refer to
Using the controller's wired discovery information
Furthermore, RAPIDS integrates with external intrusion detection systems (IDS), as follows:
Dell WIP—Dell PowerConnect W's Wireless Intrusion Protection (WIP) module integrates wireless
intrusion protection into the mobile edge infrastructure. The WIP module provides wired and wireless AP
detection, classification and containment; detects DoS and impersonation attacks; and prevents client and
network intrusions.
Cisco WLSE (1100 and 1200 IOS)—AMP fetches rogue information from the HTTP interface and gets new
AP information from SOAP API. This system provides wireless discovery information rather than rogue
detection information.
AirMagnet Enterprise—Retrieves a list of managed APs from AMP.
AirDefense—Uses the AMP XML API to keep its list of managed devices up to date.
WildPackets OmniPeek—Retrieves a list of managed APs from AMP.
Dell PowerConnect W-AirWave | User Guide
"Discovering and Adding Devices" on
Chapter 7

Using RAPIDS and Rogue Classification

page 105.
Using RAPIDS and Rogue Classification | 163

Advertisement

Table of Contents
loading

This manual is also suitable for:

Powerconnect w-airwave 7.3

Table of Contents