D-Link DWS-4026 Product Manual - Page 488

Monitoring and Managing Intrusion Detection, AP RF Scan Status, Table 311

Page 488 highlights

D-Link Unified Access System Software User Manual 12/10/09 Table 311: Peer Switch Managed AP Status Field Description Peer Switch IP Address Shows the IP address of the peer switch that manages the AP. Location The descriptive location configured for the managed AP. AP IP Address Profile Hardware Type The IP address of the AP. The AP profile applied to the AP by the switch. The Hardware ID associated with the AP hardware platform . MONITORING AND MANAGING INTRUSION DETECTION This section contains the following subsections to help manage and monitor the APs and wireless clients in the D-Link Unified Switch network and to protect against rogue devices: • AP RF Scan Status • Detected Client Status • Ad Hoc Client Status • AP Authentication Failure Status • AP De-Authentication Attack Status Status entries for the Intrusion Detection pages are collected at a point in time and eventually age out. The age value for each entry shows how long ago the switch recorded the entry. You can configure the age out time for status entries on the WLAN > Advanced Configuration > Global page. You can also manually delete status entries. AP RF SCAN STATUS The radios on each AP can periodically scan the radio frequency to collect information about other APs and wireless clients that are within range. In normal operating mode the AP always scans on the operational channel for the radio. Two other scan modes are available for each radio on the APs: • Scan Other Channels: Configures the AP to periodically leave its operational channel and scan other channels within that frequency. • Scan Sentry: Disables normal operation of the radio and performs a continuous radio scan. In this mode, no beacons are sent, and no clients are allowed to associate with the AP. When Scan Other Channels or Scan Sentry modes are enabled, the AP scans all available channels on each radio. When the scan is complete, the AP sends information it collected during the RF scan to the switch that manages it. For information about how to configure the scan mode, see "Radio" on page 417. The Unified Switch considers an access point to be a rogue if is detected during the RF scan process and is classified as a threat by one of the threat detection algorithms. To view the threat detection algorithms enabled on the system, go to the WLAN > Administration > Advanced Configuration > WIDS Security page. From the WLAN > Monitoring > Access Point > AP RF Scan Status page, you can view information about all APs detected via RF scan, including those reported as Rogues. You can sort the APs in the list based any of the column headings. For example, to group all Rogue APs together, click Status. Page 488 Monitoring and Managing Intrusion Detection Document 34CSFP6XXUWS-SWUM100-D7

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435
  • 436
  • 437
  • 438
  • 439
  • 440
  • 441
  • 442
  • 443
  • 444
  • 445
  • 446
  • 447
  • 448
  • 449
  • 450
  • 451
  • 452
  • 453
  • 454
  • 455
  • 456
  • 457
  • 458
  • 459
  • 460
  • 461
  • 462
  • 463
  • 464
  • 465
  • 466
  • 467
  • 468
  • 469
  • 470
  • 471
  • 472
  • 473
  • 474
  • 475
  • 476
  • 477
  • 478
  • 479
  • 480
  • 481
  • 482
  • 483
  • 484
  • 485
  • 486
  • 487
  • 488
  • 489
  • 490
  • 491
  • 492
  • 493
  • 494
  • 495
  • 496
  • 497
  • 498
  • 499
  • 500
  • 501
  • 502
  • 503
  • 504
  • 505
  • 506
  • 507
  • 508
  • 509
  • 510
  • 511
  • 512
  • 513
  • 514
  • 515
  • 516
  • 517
  • 518
  • 519
  • 520
  • 521
  • 522
  • 523
  • 524
  • 525
  • 526
  • 527
  • 528
  • 529
  • 530
  • 531
  • 532
  • 533
  • 534
  • 535
  • 536
  • 537
  • 538
  • 539
  • 540
  • 541
  • 542
  • 543
  • 544
  • 545
  • 546
  • 547
  • 548
  • 549
  • 550
  • 551
  • 552
  • 553
  • 554
  • 555
  • 556
  • 557
  • 558
  • 559
  • 560
  • 561
  • 562
  • 563
  • 564
  • 565
  • 566
  • 567
  • 568
  • 569
  • 570
  • 571
  • 572
  • 573
  • 574
  • 575
  • 576

D-Link Unified Access System
Software User Manual
12/10/09
Page
488
Monitoring and Managing Intrusion Detection
Document
34CSFP6XXUWS-SWUM100-D7
M
ONITORING
AND
M
ANAGING
I
NTRUSION
D
ETECTION
This section contains the following subsections to help manage and monitor the APs and wireless clients in the D-Link
Unified Switch network and to protect against rogue devices:
AP RF Scan Status
Detected Client Status
Ad Hoc Client Status
AP Authentication Failure Status
AP De-Authentication Attack Status
Status entries for the Intrusion Detection pages are collected at a point in time and eventually age out. The age value for
each entry shows how long ago the switch recorded the entry. You can configure the age out time for status entries on the
WLAN > Advanced Configuration > Global
page. You can also manually delete status entries.
AP RF S
CAN
S
TATUS
The radios on each AP can periodically scan the radio frequency to collect information about other APs and wireless clients
that are within range. In normal operating mode the AP always scans on the operational channel for the radio. Two other
scan modes are available for each radio on the APs:
Scan Other Channels
: Configures the AP to periodically leave its operational channel and scan other channels within
that frequency.
Scan Sentry
: Disables normal operation of the radio and performs a continuous radio scan. In this mode, no beacons
are sent, and no clients are allowed to associate with the AP.
When Scan Other Channels or Scan Sentry modes are enabled, the AP scans all available channels on each radio. When
the scan is complete, the AP sends information it collected during the RF scan to the switch that manages it. For information
about how to configure the scan mode, see
“Radio” on page 417
.
The Unified Switch considers an access point to be a rogue if is detected during the RF scan process and is classified as a
threat by one of the threat detection algorithms. To view the threat detection algorithms enabled on the system, go to the
WLAN > Administration > Advanced Configuration > WIDS Security
page.
From the
WLAN > Monitoring > Access Point > AP RF Scan Status
page, you can view information about all APs detected
via RF scan, including those reported as Rogues.
You can sort the APs in the list based any of the column headings. For example, to group all Rogue APs together, click
Status
.
Peer Switch IP Address
Shows the IP address of the peer switch that manages the AP.
Location
The descriptive location configured for the managed AP.
AP IP Address
The IP address of the AP.
Profile
The AP profile applied to the AP by the switch.
Hardware Type
The Hardware ID associated with the AP hardware platform .
Table 311:
Peer Switch Managed AP Status
Field
Description