Configuring Advanced Settings
D-Link
Unified Wired and Wireless Access System
Oct. 2015
Page 631
D-Link UWS User Manual
WIDS Security
The D-Link Unified Switch Wireless Intrusion Detection System (WIDS) can help detect intrusion attempts into
the wireless network and take automatic actions to protect the network.
WIDS AP Configuration
The
WIDS AP Configuration
page allows you to activate or deactivate various threat detection tests and set
threat detection thresholds in order to help detect rogue APs on the wireless network. These changes can be
done without disrupting network connectivity. Since some of the work is done by access points, the switch
needs to send messages to the APs to modify its WIDS operational properties.
Many of the tests are focused on identifying APs that are advertising managed SSIDs, but are not in fact
managed APs. Detecting such an AP means that a network is either miss-configured or that a hacker set up a
honeypot AP in the attempt to collect passwords or other secure information.
Although operational mode radios can detect most threats, the sentry radios detect the threats faster,
especially when a potential rogue is operating on a different channel from any of the managed AP radios. The
number of deployed sentry radios should be sufficient to provide coverage by one sentry radio in every
geographical location within the network. A denser sentry deployment may be desirable in order to improve
rogue or interferer signal triangulation.
Figure 395: WIDS AP Configuration
Note:
The classification settings on the WIDS AP Configuration page are part of the global
configuration on the switch and must be manually pushed to other switches in order to synchronize
that configuration.