Rogue Detection and Countermeasures 549

Countermeasures are disabled by default. You can enable them on an individual radio profile basis. To enable counter- measures on a radio profile, use the following command:

set radio-profile name countermeasures {all rogue}

The all option enables or disables countermeasures for rogues and for interfering devices. This option is equivalent to the scope of rogue detection in WSS Software Version 3.x. The rogue option enables or disables countermeasures for rogues only.

The following command enables countermeasures in radio profile radprof3 for rogues only:

23x0# set radio-profile radprof3 countermeasures rogue

success: change accepted.

To disable countermeasures on a radio profile, use the following command:

clear radio-profile name countermeasures

The following command disables countermeasures in radio profile radprof3:

23x0# clear radio-profile radprof3 countermeasures

success: change accepted.

Disabling or Reenabling Active Scan

When active scanning is enabled, the AP radios managed by the switch look for rogue devices by sending probe any frames (probes with a null SSID name), to solicit probe responses from other APs.

Active scan is enabled by default. You can disable or reenable the feature on an individual radio profile basis. To disable or reenable active scan on a radio profile, use the following command:

set radio-profile name active-scan {enable disable}

The following command disables active scan in radio profile radprof3:

23x0# set radio-profile radprof3 active-scan disable

success: change accepted.

Enabling AP Signatures

An AP signature is a set of bits in a management frame sent by an AP that identifies that AP to WSS Software. If someone attempts to spoof management packets from a Nortel AP, WSS Software can detect the spoof attempt.

AP signatures are disabled by default. To enable or disable them, use the following command:

set rfdetect signature {enable disable}

Nortel WLAN Security Switch 2300 Series Configuration Guide

Page 549
Image 549
Nortel Networks 2300 manual Disabling or Reenabling Active Scan, Enabling AP Signatures