Netgear WNDAP660 Reference Manual - Page 94

To enable and con the IDS/IPS, Configuration > IDS/IPS, Enable, Table 24.

Page 94 highlights

ProSafe Premium 3 x 3 Dual-Band Wireless-N Access Point WNDAP660 Table 24. IDS/IPS policies and policy rules (continued) Policy Description Policy Rule Threshold Notification Device probing for access points • Detection. Multiple probe requests (30 or more) are sent to 30 collect information about the wireless access point for possible future attacks. For example, it is suspect when there are too many probe requests with a different SSID from same MAC address. • Result. An attack might occur, or wireless security might become compromised. • Solution. The wireless access point does not respond to probe requests that do not contain its SSID. Trap PS poll flood attack • Attack. Multiple power save (PS)-Poll frames (50 or more) are 50 sent to the wireless access point from an address that has a spoofed MAC address of a legitimate client. • Result. Traffic that is intended for the legitimate client is sent to the attacking address and is lost. • Solution. PS-Poll frames without a corresponding traffic indication map (TIM) are rejected. Trap  To enable and configure the IDS/IPS: 1. Select Configuration > IDS/IPS. The IDS/IPS screen displays: Figure 54. 2. Select the Enable radio button. By default, the IDS/IPS is disabled. Management and Monitoring 94

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174

Management and Monitoring
94
ProSafe Premium 3 x 3 Dual-Band Wireless-N Access Point WNDAP660
To enable and configure the IDS/IPS:
1.
Select
Configuration > IDS/IPS
. The IDS/IPS screen displays:
Figure 54.
2.
Select the
Enable
radio button. By default, the IDS/IPS is disabled.
Device probing for
access points
Detection
. Multiple probe requests (30 or more) are sent to
collect information about the wireless access point for possible
future attacks. For example, it is suspect when there are too
many probe requests with a different SSID from same MAC
address.
Result
. An attack might occur, or wireless security might
become compromised.
Solution
. The wireless access point does not respond to probe
requests that do not contain its SSID.
30
Trap
PS poll flood attack
Attack
. Multiple power save (PS)–Poll frames (50 or more) are
sent to the wireless access point from an address that has a
spoofed MAC address of a legitimate client.
Result
. Traffic that is intended for the legitimate client is sent to
the attacking address and is lost.
Solution
. PS-Poll frames without a corresponding traffic
indication map (TIM) are rejected.
50
Trap
Table 24.
IDS/IPS policies and policy rules (continued)
Policy
Description
Policy Rule
Threshold
Notification