D-Link DWS-4026 Product Manual - Page 496

Table 318, Detailed Detected Client Status, Field, Description, Time Since Entry Last

Page 496 highlights

D-Link Unified Access System Software User Manual 12/10/09 Table 318: Detailed Detected Client Status Field Description MAC Address Client Status Authentication Status Threat Detection The Ethernet address of the client. Shows the client status, which can be one of the following: • Authenticated-Client is Authenticated with the system and is not Rogue. • Detected-Client is detected, not Authenticated, not rogue, and is not found in the Known Clients Database. • Known-Client is detected and found in the Known Clients Database, but is not authenticated. • Black-Listed-Client tried to associate with the system, but was rejected due to MAC authentication. • Rogue-Client failed of the enabled threat tests. Indicates whether this client is authenticated. Note: The Client Status can be Rogue, but the authentication status can still be Authenticated. Indicates whether one of the threat detection tests has been triggered for this client. If the test is disabled, the client will not be marked as a rogue, but you can still investigate why the threat was triggered. Threat Mitigation Status Indicates whether threat mitigation has been done for this client. Time Since Entry Last Shows the amount of time that has passed since any event has been received for this client Updated that updated the detected client database entry. Time Since Entry Create Client Name RSSI Signal Noise Shows the amount of time that has passed since this entry was first added to the detected clients database. Shows the name of the client, if available, from the Known Client Database. If the client is not in the database then the field is blank. If the client is authenticated with the managed AP, this field displays the last RSSI value reported by the AP with which the client is authenticated. The RSSI is a percentage from 1- 100%. A value of 0 means the AP is not detected. Last signal strength reported by the managed AP with which the client is authenticated. The possible range is -128 to 128 dBm. Last channel noise reported by the managed AP with which the client is authenticated. The possible range is -128 to 128 dBm. Probe Req Recorded Probe Collection Interval Highest Probes Detected Channel Number of probe requests recorded so far during the probe collection interval. Shows the amount of time spent in each probe collection period. The probe collection helps the switch decide whether the client is a threat. Shows the largest number of probes that the switch detected during a probe collection interval. Identifies the channel that the client is using. Auth Msgs Recorded Shows the number of IEEE 802.11 Authentication messages recorded so far during the authentication collection interval. Auth Collection Interval Shows the amount of time spent in each authentication collection period. The authentication collection helps the switch decide whether the client is a threat. Highest Auth Msgs De-Auth Msgs Recorded Shows the largest number of authentication messages that the switch detected during an authentication collection interval. Shows the number of IEEE 802.11 De-Authentication messages recorded so far during the deauthentication collection interval. Page 496 Monitoring and Managing Intrusion Detection Document 34CSFP6XXUWS-SWUM100-D7

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435
  • 436
  • 437
  • 438
  • 439
  • 440
  • 441
  • 442
  • 443
  • 444
  • 445
  • 446
  • 447
  • 448
  • 449
  • 450
  • 451
  • 452
  • 453
  • 454
  • 455
  • 456
  • 457
  • 458
  • 459
  • 460
  • 461
  • 462
  • 463
  • 464
  • 465
  • 466
  • 467
  • 468
  • 469
  • 470
  • 471
  • 472
  • 473
  • 474
  • 475
  • 476
  • 477
  • 478
  • 479
  • 480
  • 481
  • 482
  • 483
  • 484
  • 485
  • 486
  • 487
  • 488
  • 489
  • 490
  • 491
  • 492
  • 493
  • 494
  • 495
  • 496
  • 497
  • 498
  • 499
  • 500
  • 501
  • 502
  • 503
  • 504
  • 505
  • 506
  • 507
  • 508
  • 509
  • 510
  • 511
  • 512
  • 513
  • 514
  • 515
  • 516
  • 517
  • 518
  • 519
  • 520
  • 521
  • 522
  • 523
  • 524
  • 525
  • 526
  • 527
  • 528
  • 529
  • 530
  • 531
  • 532
  • 533
  • 534
  • 535
  • 536
  • 537
  • 538
  • 539
  • 540
  • 541
  • 542
  • 543
  • 544
  • 545
  • 546
  • 547
  • 548
  • 549
  • 550
  • 551
  • 552
  • 553
  • 554
  • 555
  • 556
  • 557
  • 558
  • 559
  • 560
  • 561
  • 562
  • 563
  • 564
  • 565
  • 566
  • 567
  • 568
  • 569
  • 570
  • 571
  • 572
  • 573
  • 574
  • 575
  • 576

D-Link Unified Access System
Software User Manual
12/10/09
Page
496
Monitoring and Managing Intrusion Detection
Document
34CSFP6XXUWS-SWUM100-D7
Table 318:
Detailed Detected Client Status
Field
Description
MAC Address
The Ethernet address of the client.
Client Status
Shows the client status, which can be one of the following:
Authenticated—Client is Authenticated with the system and is not Rogue.
Detected—Client is detected, not Authenticated, not rogue, and is not found in the Known
Clients Database.
Known—Client is detected and found in the Known Clients Database, but is not
authenticated.
Black-Listed—Client tried to associate with the system, but was rejected due to MAC
authentication.
Rogue—Client failed of the enabled threat tests.
Authentication Status
Indicates whether this client is authenticated.
Note:
The Client Status can be Rogue, but the authentication status can still be
Authenticated.
Threat Detection
Indicates whether one of the threat detection tests has been triggered for this client. If the test
is disabled, the client will not be marked as a rogue, but you can still investigate why the threat
was triggered.
Threat Mitigation Status
Indicates whether threat mitigation has been done for this client.
Time Since Entry Last
Updated
Shows the amount of time that has passed since any event has been received for this client
that updated the detected client database entry.
Time Since Entry
Create
Shows the amount of time that has passed since this entry was first added to the detected
clients database.
Client Name
Shows the name of the client, if available, from the Known Client Database. If the client is not
in the database then the field is blank.
RSSI
If the client is authenticated with the managed AP, this field displays the last RSSI value
reported by the AP with which the client is authenticated. The RSSI is a percentage from 1–
100%. A value of 0 means the AP is not detected.
Signal
Last signal strength reported by the managed AP with which the client is authenticated. The
possible range is –128 to 128 dBm.
Noise
Last channel noise reported by the managed AP with which the client is authenticated. The
possible range is –128 to 128 dBm.
Probe Req Recorded
Number of probe requests recorded so far during the probe collection interval.
Probe Collection
Interval
Shows the amount of time spent in each probe collection period. The probe collection helps
the switch decide whether the client is a threat.
Highest Probes
Detected
Shows the largest number of probes that the switch detected during a probe collection interval.
Channel
Identifies the channel that the client is using.
Auth Msgs Recorded
Shows the number of IEEE 802.11 Authentication messages recorded so far during the
authentication collection interval.
Auth Collection Interval
Shows the amount of time spent in each authentication collection period. The authentication
collection helps the switch decide whether the client is a threat.
Highest Auth Msgs
Shows the largest number of authentication messages that the switch detected during an
authentication collection interval.
De-Auth Msgs
Recorded
Shows the number of IEEE 802.11 De-Authentication messages recorded so far during the
deauthentication collection interval.