Wireless Access Point
Configuring the Wireless AP
375
About Blocking Rogue APs
If you classify a rogue AP as
blocked
(see
“Rogue Control List” on page 263
), then
the AP will take measures to prevent stations from staying associated to the
rogue. When the monitor radio is scanning, any time it hears a beacon from a
blocked rogue it sends out a broadcast “deauth” signal using the rogue's BSSID
and source address. This has the effect of disconnecting all of a rogue AP’s clients
approximately every 5 to 10 seconds, which is enough to make the rogue
frustratingly unusable.
The Intrusion Detection window allows you to set up
Auto Block
parameters so
that unknown APs get the same treatment as explicitly blocked APs. This is
basically a “shoot first and ask questions later” mode. By default, auto blocking is
turned off. Auto blocking provides two parameters for qualifying blocking so that
APs must meet certain criteria before being blocked. This keeps the AP from
blocking every AP that it detects. You may:
Set a minimum RSSI value for the AP — for example, if an AP has an RSSI
value of -90, it is probably a harmless AP belonging to a neighbor and not
in your building.
Block based on encryption level.
Block based on whether the AP is part of an ad hoc network or
infrastructure network.
Specify channels to be whitelisted. Rogues discovered on these channels
are excluded from auto blocking. This allows specified channels to be
freely used by customer or guests for their APs.
Sequence
number anomaly
A sender may use an Add Block Address request (ADDBA
- part of the Block ACK mechanism) to specify a sequence
number range for packets that the receiver can accept.
An attacker spoofs an ADDBA request, asking the receiver
to reset its sequence number window to a new range. This
causes the receiver to drop legitimate frames, since their
sequence numbers will not fall in that range.
Type of Attack
Description
Содержание XR Series
Страница 1: ...August 11 2015 Release 7 5 Wireless Access Point User s Guide ...
Страница 2: ......
Страница 17: ...Wireless Access Point xiii Glossary of Terms 607 Index 619 ...
Страница 18: ...Wireless Access Point xiv ...
Страница 26: ...Wireless Access Point xxii List of Figures ...
Страница 54: ...Wireless Access Point 28 Introduction ...
Страница 120: ...Wireless Access Point 94 The Web Management Interface ...
Страница 186: ...Wireless Access Point 160 Viewing Status on the Wireless AP ...
Страница 434: ...Wireless Access Point 408 Configuring the Wireless AP ...
Страница 534: ...Wireless Access Point 508 The Command Line Interface Figure 227 Configuring Radio Assurance Mode Loopback Testing ...
Страница 535: ...Wireless Access Point Appendices 509 Appendices ...
Страница 536: ...Wireless Access Point 510 Appendices Page is intentionally blank ...
Страница 544: ...Wireless Access Point 518 ...
Страница 588: ...Wireless Access Point 562 ...
Страница 601: ...Wireless Access Point 575 Declaration of Conformity Brazil XR 1000 XR 2000 XR 4000 ...
Страница 612: ...Wireless Access Point 586 ...
Страница 624: ...Wireless Access Point 598 ...
Страница 660: ...Wireless Access Point 634 Index ...
Страница 661: ......