Management and Monitoring
90
ProSafe Premium 3 x 3 Dual-Band Wireless-N Access Point WNDAP620
Unauthenticated
association Attack. Multiple unauthenticated association requests (5 or
more) that use spoofed MAC addresses of legitimate clients are
sent to the wireless access point.
Result. The client association table overflows, causing
authentication requests from legitimate clients to be denied.
Solution. The oldest clients that are stuck in the authentication
phase are removed from the table.
5Trap
Association table
overflow Attack. Multiple clients (5 or more) that use spoofed MAC
addresses of legitimate clients attempt to connect to the
wireless access point.
Result. The client association table overflows, causing
association requests from legitimate clients to be denied.
Solution. The oldest associations are removed from the table.
5Trap
Authentication
failure attack Attack. Multiple invalid authentication requests (5 or more) that
use the spoofed MAC address of a legitimate client are sent to
the wireless access point.
Result. The client is disconnected from the wireless access
point.
Solution. The wireless access point determines if the legitimate
client is already connected before processing an authentication
request.
5Trap
Deauthentication
broadcast attack Attack. Multiple deauthentication frames (5 or more) that use
the spoofed MAC address of the wireless access point are sent
to legitimate clients.
Result. Clients are disconnected from the wireless access
point.
Note: The IDS detects this attack, but the IPS does not take action
against this attack.
5Trap
Disassociation flood Attack. Multiple disassociation frames (5 or more) that use the
spoofed MAC address of the wireless access point are sent to a
legitimate client.
Result. The client is disconnected from the wireless access
point.
Note: The IDS detects this attack, but the IPS does not take action
against this attack.
5Trap
Malformed 802.11
packets detected Detection. Multiple malformed packets (5 or more) are sent to
the wireless access point.
Result. Clients behave unexpectedly or crash.
Solution. The wireless access point drops the malformed
packets.
5Trap
Table 24. IDS/IPS policies and policy rules (continued)
Policy Description Policy Rule
Threshold Notification