Dell PowerConnect W-IAP92 Dell Instant 5.0.3.0-1.1.0.0 User Guide - Page 107

Intrusion Detection System, Rogue AP Detection and Classification, Rogue Containment

Page 107 highlights

Chapter 16 Intrusion Detection System Intrusion Detection System (IDS) is a feature that monitors the network for the presence of unauthorized IAPs and clients. It also logs information about the unauthorized IAPs and clients, and generates reports based on the logged information. Rogue AP Detection and Classification The most important IDS functionality offered in the Dell Instant network is the ability to detect rogue APs, interfering APs, and other devices that can potentially disrupt network operations. An AP is considered to be a rogue AP if it is both unauthorized and plugged into the wired side of the network. An AP is considered to be an interfering AP if it is seen in the RF environment but is not connected to the wired network. While the interfering AP can potentially cause RF interference, it is not considered a direct security threat since it is not connected to the wired network. However, an interfering AP may be reclassified as a rogue AP. Figure 84 Intrusion Detection Rogue Containment Enable or disable rogue containment on the Instant network. By default, this is disabled. NOTE: The rouge containment is supported only when the IAPs are in the monitor mode. Figure 85 Rogue Containment Containment Methods You can enable wired and wireless containments to prevent unauthorized stations from connecting to your Instant network. Dell PowerConnect W-Instant Access Point 5.0.3.0-1.1.0.0 | User Guide Intrusion Detection System | 107

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140

Dell PowerConnect W-Instant Access Point 5.0.3.0-1.1.0.0
|
User Guide
Intrusion Detection System
|
107
Chapter 16
Intrusion Detection System
Intrusion Detection System (IDS) is a feature that monitors the network for the presence of unauthorized IAPs
and clients. It also logs information about the unauthorized IAPs and clients, and generates reports based on the
logged information.
Rogue AP Detection and Classification
The most important IDS functionality offered in the Dell Instant network is the ability to detect rogue APs,
interfering APs, and other devices that can potentially disrupt network operations. An AP is considered to be a
rogue AP if it is both unauthorized and plugged into the wired side of the network. An AP is considered to be an
interfering AP if it is seen in the RF environment but is not connected to the wired network. While the
interfering AP can potentially cause RF interference, it is not considered a direct security threat since it is not
connected to the wired network. However, an interfering AP may be reclassified as a rogue AP.
Figure 84
Intrusion Detection
Rogue Containment
Enable or disable rogue containment on the Instant network. By default, this is disabled.
Figure 85
Rogue Containment
Containment Methods
You can enable wired and wireless containments to prevent unauthorized stations from connecting to your
Instant network.
NOTE:
The rouge containment is supported only when the IAPs are in the monitor mode.