359
DWS-1008 User’s Manual
D-Link Systems, Inc.
Rogue Detection and Countermeasures
Disallowed Devices or SSIDs
You can configure the following types of lists to explicitly allow specific devices or SSIDs:
• Permitted SSID list - MSS generates a message if an SSID that is not on the list is
detected.
• Permitted vendor list - MSS generates a message if an AP or wireless client with an
OUI that is not on the list is detected.
• Client black list - MSS prevents clients on the list from accessing the network through a
switch. If the client is placed on the black list dynamically by MSS due to an association,
reassociation or disassociation flood, MSS generates a log message.
By default, these lists are empty and all SSIDs, vendors, and clients are allowed.
Displaying Statistics Counters
To display IDS and DoS statistics counters, use the
show rfdetect counters
commands.
IDS Log Message Examples
The table below shows examples of the log messages generated by IDS.
Message Type Example Log Message
Probe message
flood
Client aa:bb:cc:dd:ee:ff is sending probe
message flood.
Seen by AP on port 2, radio 1 on channel 11 with
RSSI -53.
Authentication
message flood
Client aa:bb:cc:dd:ee:ff is sending authentication
message flood.
Seen by AP on port 2, radio 1 on channel 11 with
RSSI -53.
Null data
message flood
Client aa:bb:cc:dd:ee:ff is sending null data
message flood.
Seen by AP on port 2, radio 1 on channel 11 with
RSSI -53.
Management
frame 6 flood
Client aa:bb:cc:dd:ee:ff is sending rsvd mgmt
frame 6 message flood.
Seen by AP on port 2, radio 1 on channel 11 with
RSSI -53.
Summary of Contents for DWS-1008
Page 1: ......