SonicPoint > IDS

Rogue Access Points have emerged as one of the most serious and insidious threats to wireless security. In general terms, an access point is considered rogue when it has not been authorized for use on a network. The convenience, affordability and availability of non-secure access points, and the ease with which they can be added to a network creates an easy environment for introducing rogue access points. Specifically, the real threat emerges in a number of different ways, including unintentional and unwitting connections to the rogue device, transmission of sensitive data over non-secure channels, and unwanted access to LAN resources. So while this doesn't represent a deficiency in the security of a specific wireless device, it is a weakness to the overall security of wireless networks.

Intrusion Detection Services (IDS) greatly increase the security capabilities of the SonicWall security appliance because it enables the appliance to recognize and take countermeasures against the most common types of illicit wireless activity. IDS reports on all access points the SonicWall security appliance can find by scanning the 802.11a/b/g/n/ac/af radio bands on the SonicPoints.

The SonicPoint > IDS page reports on all access points detected by the SonicWall security appliance and its associated SonicPoints, and provides the ability to authorize legitimate access points.

The table below describes the entities that are displayed on the SonicPoint > IDS page.

 

SonicPoint > ID Page Elements

Table Column or Entity

Description

Entity

Page Navigation

Allows you to quickly navigate to the next or previous page. You can enter a value to pass large entries. For example, if you have 10 pages, you can enter 7 in the Item text field to view page 7.

Refresh button

Refreshes the screen to display the most current list of access points in your network.

Scan All... button

Initiates a scan all operation to identify.

Discovered Access Points Table

View Style: SonicPoint: Drop-down menu

If you have more than one SonicPoint, you can select an individual device from the SonicPoint list to limit the Discovered Access Points table to display only scan results from that SonicPoint. Select All SonicPoints to display scan results from all SonicPoints.

SonicPoint

Available when All SonicPoints is selected in the View Style drop-down.

The SonicPoint that detected the access point.

MAC Address (BSSID)

The MAC address of the radio interface of the detected access point.

SSID

The radio SSID of the access point.

Type

The range of radio bands used by the access point, 2.4 GHz or 5 GHz.

Channel

The radio channel used by the access point.

Authentication

The authentication type.

Cipher

The cipher mode.

Manufacturer

The manufacturer of the access point.

Signal Strength

The strength of the detected radio signal.

Max Rate

The fastest allowable data rate for the access point radio, typically 54 Mbps.

Authorize

When the Edit icon is clicked, the access point is added to the address object group of authorized access points.

Topics: