Netgear WNDAP620 Reference Manual - Page 89

Con Wireless Intrusion Detection and Prevention, Settings

Page 89 highlights

ProSafe Premium 3 x 3 Dual-Band Wireless-N Access Point WNDAP620 Configure Wireless Intrusion Detection and Prevention • Configure Wireless Intrusion Detection and Prevention Policy Settings • Configure Wireless Intrusion Detection and Prevention Mail Settings • Monitor Traps, Counters, and Ad Hoc Networks Configure Wireless Intrusion Detection and Prevention Policy Settings The wireless access point provides a wireless intrusion detection system (WIDS) and wireless intrusion prevention system (WIPS) to detect and mitigate wireless attacks. These intrusion systems are referred to as IDS/IPS. If enabled, the IDS recognizes multiple types of wireless attacks, and the IPS automatically neutralizes many attacks. Attacks are covered by preconfigured policy rules. When an attack occurs, the wireless access point can notify a network administrator though an email. The following table lists all IDS/IPS policies with their policy rules. Most of these policies provide protection against denial of service (DoS) attacks. You can enable or disable IDS/IPS policies, but both the policies and the policy rules are not configurable. All thresholds are measured over a short period. For the IDS/IPS to send a notification according to the policy rule, you first need to configure the email settings (see Configure Wireless Intrusion Detection and Prevention Mail Settings on page 95). Table 24. IDS/IPS policies and policy rules Policy Description Policy Rule Threshold Notification Authentication flood • • • Attack. Multiple authentication requests (5 or more) that use 5 spoofed MAC addresses of legitimate clients are sent to the wireless access point. Result. The client association table overflows, causing authentication requests from legitimate clients to be denied. Solution. The oldest clients that are stuck in the authentication phase are removed from the table. Trap Association flood • Attack. Multiple association requests (5 or more) that use 5 spoofed MAC addresses of legitimate clients are sent to the wireless access point. • Result. The client association table overflows, causing association requests from legitimate clients to be denied. • Solution. The oldest associations are removed from the table. Trap Management and Monitoring 89

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172

Management and Monitoring
89
ProSafe Premium 3 x 3 Dual-Band Wireless-N Access Point WNDAP620
Configure Wireless Intrusion Detection and Prevention
Configure Wireless Intrusion Detection and Prevention Policy Settings
Configure Wireless Intrusion Detection and Prevention Mail Settings
Monitor Traps, Counters, and Ad Hoc Networks
Configure Wireless Intrusion Detection and Prevention Policy
Settings
The wireless access point provides a wireless intrusion detection system (WIDS) and
wireless intrusion prevention system (WIPS) to detect and mitigate wireless attacks. These
intrusion systems are referred to as IDS/IPS.
If enabled, the IDS recognizes multiple types of wireless attacks, and the IPS automatically
neutralizes many attacks. Attacks are covered by preconfigured policy rules. When an attack
occurs, the wireless access point can notify a network administrator though an email.
The following table lists all IDS/IPS policies with their policy rules. Most of these policies
provide protection against denial of service (DoS) attacks. You can enable or disable IDS/IPS
policies, but both the policies and the policy rules are not configurable.
All thresholds are measured over a short period. For the IDS/IPS to send a notification according
to the policy rule, you first need to configure the email settings (see
Configure Wireless Intrusion
Detection and Prevention Mail Settings
on page 95).
Table 24.
IDS/IPS policies and policy rules
Policy
Description
Policy Rule
Threshold
Notification
Authentication flood
Attack
. Multiple authentication requests (5 or more) that use
spoofed MAC addresses of legitimate clients are sent to the
wireless access point.
Result
. The client association table overflows, causing
authentication requests from legitimate clients to be denied.
Solution
. The oldest clients that are stuck in the authentication
phase are removed from the table.
5
Trap
Association flood
Attack
. Multiple association requests (5 or more) that use
spoofed MAC addresses of legitimate clients are sent to the
wireless access point.
Result
. The client association table overflows, causing
association requests from legitimate clients to be denied.
Solution
. The oldest associations are removed from the table.
5
Trap