D-Link DWS-1008 Product Manual - Page 399

Countermeasures, Summary of Rogue Detection Features

Page 399 highlights

Countermeasures You can enable MSS to use countermeasures against rogues. Countermeasures consist of packets that interfere with a client's ability to use the rogue. Countermeasures are disabled by default. You can enable them on an individual radio-profile basis. When you enable them, all devices of interest that are not in the known devices list become viable targets for countermeasures. Countermeasures can be enabled against all rogue and interfering devices, against rogue devices only, or against devices explicitly configured in the switch's attack list. Summary of Rogue Detection Features The table below lists the rogue detection features in MSS. Rogue Detection Feature Classification Permitted vendor list Permitted SSID list Client black list Attack list Ignore list Countermeasures Active scan D-Link AP signature Log messages and traps Description MSS can classify third-party APs as rogues or interfering devices. A rogue is a third-party AP whose MAC address MSS knows from the wired side of the network. An interfering device does not have a MAC address known on the wired side. MSS can detect rogue clients, locate their APs, and issue countermeasures against the APs. List of OUIs to allow on the network. An OUI is the first three octets of a MAC address and uniquely identifies an AP's or client's vendor. List of SSIDs allowed on the network. MSS can issue countermeasures against third-party APs sending traffic for an SSID that is not on the list. List of client or AP MAC addresses that are not allowed on the wireless network. MSS drops all packets from these clients or APs. List of AP MAC addresses to attack. MSS can issue countermeasures against these APs whenever they are detected on the network. List of MAC addresses to ignore during RF detection. MSS does not classify devices on this list as rogues or interfering devices, and does not issue countermeasures against them. Packets sent by D-Link APs to interfere with the operation of a rogue or interfering device. Countermeasures are configurable on a radio-profile basis. Active scan sends probe any requests (probes with a null SSID name) to look for rogue APs. Active scan is configurable on a radio-profile basis. Value in an AP's management frames that identifies the AP to MSS. AP signatures help prevent spoofing of the AP MAC address. Messages and traps for rogue activity. Applies To Third-Party APs Clients Yes Yes Yes No Yes Yes Yes Yes Yes No Yes Yes Yes Yes Yes No No No Yes Yes D-Link DWS-1008 User Manual 380

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435
  • 436
  • 437
  • 438
  • 439
  • 440
  • 441
  • 442
  • 443
  • 444
  • 445
  • 446
  • 447
  • 448
  • 449
  • 450
  • 451
  • 452
  • 453
  • 454
  • 455
  • 456
  • 457
  • 458
  • 459
  • 460
  • 461
  • 462
  • 463
  • 464
  • 465
  • 466
  • 467
  • 468
  • 469
  • 470
  • 471
  • 472
  • 473
  • 474
  • 475
  • 476
  • 477
  • 478
  • 479
  • 480
  • 481
  • 482
  • 483
  • 484
  • 485
  • 486
  • 487
  • 488
  • 489
  • 490
  • 491
  • 492
  • 493
  • 494
  • 495
  • 496
  • 497
  • 498
  • 499
  • 500
  • 501
  • 502

D-Link DWS-1008 User Manual
²80
Countermeasures
You can enable MSS to use countermeasures against rogues. Countermeasures consist of packets
that interfere with a client’s ability to use the rogue. Countermeasures are disabled by default. You can
enable them on an individual radio-profile basis. When you enable them, all devices of interest that are
not in the known devices list become viable targets for countermeasures.
Countermeasures can be enabled against all rogue and interfering devices, against rogue devices only,
or against devices explicitly configured in the switch’s attack list.
Summary of Rogue Detection Features
The table below lists the rogue detection features in MSS.
Rogue Detection
Feature
Description
Applies To
Third-Party APs
Clients
Classification
MSS can classify third-party APs as rogues or
interfering devices. A rogue is a third-party AP whose
MAC address MSS knows from the wired side of the
network. An interfering device does not have a MAC
address known on the wired side. MSS can detect rogue
clients, locate their APs, and issue countermeasures
against the APs.
Yes
Yes
Permitted vendor list
List of OUIs to allow on the network. An OUI is the first
three octets of a MAC address and uniquely identifies
an AP’s or client’s vendor.
Yes
No
Permitted SSID list
List of SSIDs allowed on the network. MSS can issue
countermeasures against third-party APs sending
traffic for an SSID that is not on the list.
Yes
Yes
Client black list
List of client or AP MAC addresses that are not allowed
on the wireless network. MSS drops all packets from
these clients or APs.
Yes
Yes
Attack list
List of AP MAC addresses to attack. MSS can issue
countermeasures against these APs whenever they
are detected on the network.
Yes
No
Ignore list
List of MAC addresses to ignore during RF detection.
MSS does not classify devices on this list as rogues or
interfering devices, and does not issue countermeasures
against them.
Yes
Yes
Countermeasures
Packets sent by D-Link APs to interfere with the operation
of a rogue or interfering device. Countermeasures are
configurable on a radio-profile basis.
Yes
Yes
Active scan
Active scan sends probe any requests (probes with a
null SSID name) to look for rogue APs.
Active scan is configurable on a radio-profile basis.
Yes
No
D-Link AP signature
Value in an AP’s management frames that identifies
the AP to MSS. AP signatures help prevent spoofing of
the AP MAC address.
No
No
Log messages and
traps
Messages and traps for rogue activity.
Yes
Yes