D-Link DWS-4026 Product Manual - Page 524

WIDS Security, WIDS AP Configuration, ECURITY

Page 524 highlights

D-Link Unified Access System Software User Manual 12/10/09 Field AP Profiles Known Client Captive Portal RADIUS Client QoS ACL Qos DiffServ Table 339: Peer Switch Configuration Enable/Disable Description Enable this field to include all AP profiles in the configuration that the switch pushes to its peers. The AP profile includes the global AP settings, such as the hardware type, Radio settings, VAP and Wireless Network settings, and QoS settings. To view the local AP Profile settings, click the WLAN > Administration > Advanced Configuration > AP Profile tab. Enable this field to include the Known Client Database in the configuration that the switch pushes to its peers. To view the contents of the local AP Database, click the WLAN > Administration > Advanced Configuration > Clients > Known Client page. Enable this field to include the Captive Portal information in the configuration that the switch pushes to its peers. To view the Captive Portal settings on the local switch, click the pages available in the Security > Captive Portal folder. Note: You can access the Captive Portal pages from either the LAN or WLAN tabs. Enable this field to include the Client RADIUS information in the configuration that the switch pushes to its peers. To view the Client RADIUS settings on the local switch, click the pages available in the LAN > Security > RADIUS folder. Enable this field to include the QoS ACLs in the configuration that the switch pushes to its peers. To view the ACL settings on the local switch, click the pages available in the LAN > Access Control Lists folder. Enable this field to include the Diffserv classes, services, and policies in the configuration that the switch pushes to its peers. To view the DiffServ settings on the local switch, click the pages available in the LAN > QoS > Differentiated Services folder. WIDS SECURITY The D-Link Unified Switch Wireless Intrusion Detection System (WIDS) can help detect intrusion attempts into the wireless network and take automatic actions to protect the network. WIDS AP Configuration The WIDS AP Configuration page allows you to activate or deactivate various threat detection tests and set threat detection thresholds in order to help detect rogue APs on the wireless network. These changes can be done without disrupting network connectivity. Since some of the work is done by access points, the switch needs to send messages to the APs to modify its WIDS operational properties. The classification settings on the WIDS AP Configuration page are part of the global configuration on the switch and must be manually pushed to other switches in order to synchronize that configuration. Many of the tests are focused on identifying APs that are advertising managed SSIDs, but are not in fact managed APs. Detecting such an AP means that a network is either miss-configured or that a hacker set up a honeypot AP in the attempt to collect passwords or other secure information. Page 524 Configuring Advanced Settings Document 34CSFP6XXUWS-SWUM100-D7

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435
  • 436
  • 437
  • 438
  • 439
  • 440
  • 441
  • 442
  • 443
  • 444
  • 445
  • 446
  • 447
  • 448
  • 449
  • 450
  • 451
  • 452
  • 453
  • 454
  • 455
  • 456
  • 457
  • 458
  • 459
  • 460
  • 461
  • 462
  • 463
  • 464
  • 465
  • 466
  • 467
  • 468
  • 469
  • 470
  • 471
  • 472
  • 473
  • 474
  • 475
  • 476
  • 477
  • 478
  • 479
  • 480
  • 481
  • 482
  • 483
  • 484
  • 485
  • 486
  • 487
  • 488
  • 489
  • 490
  • 491
  • 492
  • 493
  • 494
  • 495
  • 496
  • 497
  • 498
  • 499
  • 500
  • 501
  • 502
  • 503
  • 504
  • 505
  • 506
  • 507
  • 508
  • 509
  • 510
  • 511
  • 512
  • 513
  • 514
  • 515
  • 516
  • 517
  • 518
  • 519
  • 520
  • 521
  • 522
  • 523
  • 524
  • 525
  • 526
  • 527
  • 528
  • 529
  • 530
  • 531
  • 532
  • 533
  • 534
  • 535
  • 536
  • 537
  • 538
  • 539
  • 540
  • 541
  • 542
  • 543
  • 544
  • 545
  • 546
  • 547
  • 548
  • 549
  • 550
  • 551
  • 552
  • 553
  • 554
  • 555
  • 556
  • 557
  • 558
  • 559
  • 560
  • 561
  • 562
  • 563
  • 564
  • 565
  • 566
  • 567
  • 568
  • 569
  • 570
  • 571
  • 572
  • 573
  • 574
  • 575
  • 576

D-Link Unified Access System
Software User Manual
12/10/09
Page
524
Configuring Advanced Settings
Document
34CSFP6XXUWS-SWUM100-D7
WIDS S
ECURITY
The D-Link Unified Switch Wireless Intrusion Detection System (WIDS) can help detect intrusion attempts into the wireless
network and take automatic actions to protect the network.
WIDS AP Configuration
The
WIDS AP Configuration
page allows you to activate or deactivate various threat detection tests and set threat detection
thresholds in order to help detect rogue APs on the wireless network. These changes can be done without disrupting network
connectivity. Since some of the work is done by access points, the switch needs to send messages to the APs to modify its
WIDS operational properties.
Many of the tests are focused on identifying APs that are advertising managed SSIDs, but are not in fact managed APs.
Detecting such an AP means that a network is either miss-configured or that a hacker set up a honeypot AP in the attempt
to collect passwords or other secure information.
AP Profiles
Enable this field to include all AP profiles in the configuration that the switch
pushes to its peers. The AP profile includes the global AP settings, such as
the hardware type, Radio settings, VAP and Wireless Network settings, and
QoS settings.
To view the local AP Profile settings, click the
WLAN > Administration >
Advanced Configuration > AP Profile
tab.
Known Client
Enable this field to include the Known Client Database in the configuration
that the switch pushes to its peers.
To view the contents of the local AP Database, click the
WLAN >
Administration > Advanced Configuration > Clients > Known Client
page.
Captive Portal
Enable this field to include the Captive Portal information in the configuration
that the switch pushes to its peers.
To view the Captive Portal settings on the local switch, click the pages
available in the
Security > Captive Portal
folder.
Note:
You can access the Captive Portal pages from either the LAN or
WLAN tabs.
RADIUS Client
Enable this field to include the Client RADIUS information in the configuration
that the switch pushes to its peers.
To view the Client RADIUS settings on the local switch, click the pages
available in the
LAN > Security > RADIUS
folder.
QoS ACL
Enable this field to include the QoS ACLs in the configuration that the switch
pushes to its peers.
To view the ACL settings on the local switch, click the pages available in the
LAN > Access Control Lists
folder.
Qos DiffServ
Enable this field to include the Diffserv classes, services, and policies in the
configuration that the switch pushes to its peers.
To view the DiffServ settings on the local switch, click the pages available in
the
LAN > QoS > Differentiated Services
folder.
The classification settings on the WIDS AP Configuration page are part of the global configuration on the
switch and must be manually pushed to other switches in order to synchronize that configuration.
Table 339:
Peer Switch Configuration Enable/Disable
Field
Description