353
DWS-1008 User’s Manual
D-Link Systems, Inc.
Rogue Detection and Countermeasures
The following example shows the client black list on switch:
DWS-1008#
show rfdetect black-list
Total number of entries: 1
Blacklist MAC
Type
Port TTL
------------------------------------------------------------------------
11:22:33:44:55:66 configured
- -
11:23:34:45:56:67 assoc req flood 3 25
To remove a MAC address from the client black list, use the following command:
clear
rfdetect
black-list
mac-addr
The following command removes MAC address 11:22:33:44:55:66 from the black list:
DWS-1008#
clear rfdetect black-list 11:22:33:44:55:66
success: 11:22:33:44:55:66 is no longer blacklisted.
Configuring an Attack List
The attack list specifies the MAC address of devices that MSS should issue countermeasures
against whenever the devices are detected on the network. The attack list can contain the
MAC addresses of APs and clients.
By default, the attack list is empty. The attack list applies only to the switch on which the list
is configured. DWS-1008 switches do not share attack lists.
To add an entry to the list, use the following command:
set
rfdetect
attack-list
mac-addr
The following command adds MAC address aa:bb:cc:44:55:66 to the attack list:
DWS-1008#
set rfdetect attack-list 11:22:33:44:55:66
success: MAC 11:22:33:44:55:66 is now in attacklist.
To display the attack list, use the following command:
show rfdetect attack-list
The following example shows the attack list on switch:
DWS-1008#
show rfdetect attack-list
Total number of entries: 1
Attacklist MAC Port/Radio/Chan RSSI SSID
-------------------------------------------------------------------------------
11:22:33:44:55:66 dap 2/1/11
-53 rogue-ssid
Summary of Contents for DWS-1008
Page 1: ......