
226 | Intrusion Detection AOS-W Instant 6.3.1.1-4.0 | User Guide
Containment Methods
You can enable wired and wireless containments to prevent unauthorized stations from connecting to your AOS-W
Instant network.
AOS-W Instant supports the following types of containment mechanisms:
l Wired containment— When enabled, AOS-W Instant Access Points generate ARP packets on the wired network
to contain wireless attacks.
l Wireless containment— When enabled, the system attempts to disconnect all clients that are connected or
attempting to connect to the identified Access Point.
n None— Disables all the containment mechanisms.
n Deauthenticate only— With deauthentication containment, the Access Point or client is contained by
disrupting the client association on the wireless interface.
n Tarpit containment— With Tarpit containment, the Access Point is contained by luring clients that are
attempting to associate with it to a tarpit. The tarpit can be on the same channel or a different channel as the
Access Point being contained.
Figure 75 Containment Methods
Configuring IDSUsing CLI
To configure IDS using CLI:
(Instant Access Point)(config)# ids
(Instant Access Point)(IDS)# infrastructure-detection-level <type>
(Instant Access Point)(IDS)# client-detection-level <type>
(Instant Access Point)(IDS)# infrastructure-protection-level <type>
(Instant Access Point)(IDS)# client-protection-level <type>
Komentarze do niniejszej Instrukcji