No relevant resource is found in the selected language.

This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. Read our privacy policy>Search

Reminder

To have a better experience, please upgrade your IE browser.

upgrade

Fat AP and Cloud AP V200R008C00 CLI-based Configuration Guide

Rate and give feedback :
Huawei uses machine translation combined with human proofreading to translate this document to different languages in order to help you better understand the content of this document. Note: Even the most advanced machine translation cannot match the quality of professional translators. Huawei shall not bear any responsibility for translation accuracy and it is recommended that you refer to the English document (a link for which has been provided).
Wireless Intrusion Detection

Wireless Intrusion Detection

Monitor APs can be configured to prevent intrusion to the network. When configured, the wireless intrusion detection system (WIDS) can detect unauthorized users and APs by periodically listen on wireless signals. The AP obtains information about wireless devices and can take countermeasures on unauthorized devices.

Before configuring WIDS on an AP, configure the working mode of the AP.

An AP can work in two modes:
  • normal: indicates the normal mode.
    • If the air scan function is disabled on a radio, including WIDS and terminal location, the radio is used to transmit common WLAN services.
    • If the air scan function is enabled on a radio, the radio transmits common WLAN services and also implements detection. Transmission of common WLAN services may be affected.
  • monitor: indicates the monitor mode.

    In this mode, the radio can only transmit WLAN services scanned by the air interface but cannot transmit common WLAN services.

Intrusion detection consists of two phases: wireless device identification and rogue device identification.

Wireless Device Identification

An AP enabled with WIDS can determine the types of surrounding wireless device based on detected 802.11 frames. The wireless device identification process is as follows:
  1. Configure the working mode of an AP and enable WIDS.
  2. The AP listens on frames sent from neighboring wireless devices to collect information about them. The AP determines frame types and device types according to the received 802.11 MAC frames. For details about the 802.11 MAC frame format, see 802.11 Standards.

    An AP can identify the following device types: AP, STA, wireless bridge, and ad-hoc device.
    • Wireless bridge: an AP that provides wireless distribution system (WDS) service.
    • Ad-hoc device: a device on an ad-hoc network. An ad-hoc network is a temporary wireless network composed of several devices with wireless network adapters, as shown in Figure 12-1.
      Figure 12-1  Ad-hoc network

    An AP identifies device types in the following ways:

    • When receiving a Probe Request, Association Request or Reassociation Request frame, the AP determines whether the sender is an ad-hoc device or a STA according to the network type specified in the Frame Body field of the 802.11 MAC frame.
      • Ad-hoc: The network type is independent basic service set (IBSS).
      • STA: The network type is basic service set (BSS).
    • When receiving a Beacon, Probe Response, Association Response, or Reassociation Response frame, the AP determines whether the sender is an ad-hoc device or AP according to the network type specified in the Frame Body field of the 802.11 MAC frame.
      • Ad-hoc: The network type is IBSS.
      • AP: The network type is BSS.
    • The AP listens on all 802.11 data frames and checks the DS fields of the data frames to determine whether the sender is an ad-hoc device, wireless bridge, STA, or AP.
      • Ad-hoc device: In the Frame Control field of the 802.11 MAC frame, both the To DS and From DS fields are 0.
      • Wireless bridge: In the Frame Control field of the 802.11 MAC frame, both the To DS and From DS fields are 1.
      • STA: In the Frame Control field of the 802.11 MAC frame, the To DS field 1 and the From DS field is 0.
      • AP: In the Frame Control field of the 802.11 MAC frame, the To DS field is 0 and the From DS field is 1.

Rogue Device Identification

  • Authorized AP: a local AP or an AP in the WIDS whitelist

  • Authorized wireless bridge: a local wireless bridge or a wireless bridge in the WIDS whitelist

  • Authorized STA: a STA associated with an authorized AP

  • Rogue AP: an AP that is not in the WIDS whitelist and has the same SSID as a local AP or has a spoofing SSID

  • Rogue wireless bridge: a wireless bridge that is not in the WIDS whitelist and has the same SSID as a local wireless bridge or has a spoofing SSID

  • Rogue STA: a STA associated with a rogue AP

  • Rogue ad-hoc device: all ad-hoc devices detected
  • Interference AP: an AP that is not an authorized AP or a rogue AP
  • Interference wireless bridge: a wireless bridge that is not an authorized wireless bridge or a rogue wireless bridge
  • Interference STA: a STA associated with an interference AP
NOTE:

An AP can implement countermeasures on rogue devices to prevent them from accessing the network. For details about countermeasures, see Wireless Intrusion Prevention

Translation
Download
Updated: 2019-01-11

Document ID: EDOC1000176006

Views: 115713

Downloads: 309

Average rating:
This Document Applies to these Products
Related Documents
Related Version
Share
Previous Next