BelAir20E User Guide
Wi-Fi AP Security
April 2, 2012
Confidential
Document Number BDTM02201-A01 Standard
By default, the secure port mode is
disabled
.
Note: Typically, you provision the secure MAC white list before enabling the
secure port mode. This ensures that wireless clients that are already
associated do not lose their connection to the Internet.
Auto-secure Gateway
/interface/wifi-<n>-<m>/set ssid <ssid_index>
auto-secure-gateway {enabled|disabled}
Use this command only if you want to automatically discover the MAC
addresses of the Internet gateway(s) or router(s) in your network. To use this
command, you must set the ROUTER_IP option (DHCP option 3) on the
DHCP server in your network.
Use the
show ssid table
command to determine
<ssid_index>
.
This command starts the process of detecting the MAC addresses of the
gateway for each VLAN in the system. Once it determines the MAC address, it
adds it to the secure MAC white list. This feature also continuously monitors
for changes in the gateway's MAC address updates the secure MAC white list
accordingly.
By default, the auto-secure gateway functionality mode is
disabled
.
Note: If you are automatically discovering the MAC addresses of your
network gateways, then you typically enable auto-secure gateway before
enabling the secure port mode. This ensures that wireless clients that
are already associated do not lose their connection to the Internet.
Protecting against
Denial of Service
Attacks
The BelAir20E provides protection against the following types of Denial of
Service (DoS) attacks:
• deauthentication DoS, where deauthentication packets are maliciously sent
to the BelAir platform causing it to terminate wireless sessions
The BelAir20E also automatically generates alarms when it detects the
following conditions:
• If the BelAir20E detects more than 600 DHCP requests within 30 seconds,
it raises a
DHCP_STARVATION
alarm.
• If the BelAir20E detects a client with a MAC address that matches any of the
addresses in the secure MAC white list, it raises a
SECURE_MAC_SPOOF
alarm.