
All contents are Copyright © 1992–2005 Cisco Systems, Inc. All rights reserved. This document is Cisco Public Information. Page 4 of 10
●
Automated discovery—CiscoWorks WLSE Express automatically discovers Cisco Aironet access points, bridges, and switches connected to
access points using Cisco Discovery Protocol. Discovery may be scheduled or run on demand.
●
Configuration archive—The CiscoWorks WLSE Express is able to store the last four configuration versions for each managed access point,
allowing configuration tasks to be undone.
●
VLAN configuration—VLANs on access points may be configured and monitored, allowing differentiation of LAN policies and services,
such as security and quality of service (QoS), for different users on enterprise and public-access VLANs.
●
MBSSID Support—CiscoWorks WLSE Express supports the configuration of multiple broadcast SSIDs. It supports up to 8 broadcast
Service Set Identifications (SSIDs) per access point.
●
Customizable thresholds—Administrators may define different faults and performance thresholds for specific sites and groups accompanied
by specific actions and fault priorities. A centralized fault screen simplifies quick resolution of problems. Various WLAN health indicators
such as network load, RF usage, errors, and client associations can be monitored.
●
Fault status—CiscoWorks WLSE Express provides a centralized view of all access points and device groups. Color coding and group icons
indicate fault status. Faults may be filtered and sorted by priority to facilitate viewing and resolving problems.
●
Fault notification—Fault notification and forwarding are implemented with syslog messages, SNMP traps, and e-mail.
●
Switch monitoring—Switches connected to access points are monitored for availability and the utilization of ports, CPU, and memory.
Security and WLAN Intrusion Detection
Organizations need to protect their RF environment and data networks from unauthorized access. Unauthorized (rogue) access points installed
by employees or intruders create security breaches that put the entire network at risk. WLAN IDS quickly detects, locates, and automatically
shuts down rogue access points. CiscoWorks WLSE Express provides effective rogue access-point switch-port tracing by monitoring and using
the clients that are associated to rogue access points, thus providing a means of containing the rogue access point by shutting down the switch
port connected to the rogue access point. Rogue access points can be filtered by Received Signal Strength Indicator (RSSI) threshold to avoid
triggering alarms for access points that might be a neighboring network. CiscoWorks WLSE will also periodically monitor for changes in the
status of rogue access points that are marked “Friendly” to alert the administrator in case its location and RSSI values change.
CiscoWorks WLSE Express detects unauthorized WLAN ad-hoc networks, and locates and identifies which wireless clients are participating in
the network. It also detects clients spoofing authorized MAC addresses and generates notifications. CiscoWorks WLSE Express monitors per-
channel excess wireless management frames such as excess association, disassociation, probe requests, responses, and authentication and de-
authentication frames that may signal WLAN attacks such as denial-of-service (DoS) and “man-in-the-middle” attacks. EAP over LAN
(EAPOL) flood-message monitoring provides a means to detect excess authentications requests by an intruder.
CiscoWorks WLSE Express provides a WLAN IDS dashboard that acts as a launch pad for all WLAN IDS features. The dashboard provides a
summary of all WLAN IDS alarms. In addition, it displays WLAN IDS reports pertaining to rogue access points, unauthorized ad-hoc networks,
and unregistered clients, which can be exported using comma separated value (CSV), PDF, and XML formats. These reports provide detailed
information including the estimated location of the WLAN IDS fault, which access point detected it, its channel, and its basic service set
identifier (BSSID). Administrators can select and enable specific WLAN IDS events they are interested in through a WLAN IDS profile. These
WLAN IDS profiles can be customized per location to provide greater flexibility and control. Notifications can be sent through e-mail, syslog,
or SNMP trap messages.
WLAN IDS protection can be tailored to suit individual needs:
●
Integrated WLAN IDS—Standard Cisco Aironet access points are deployed with the radio (IEEE 802.11a, b, or g) placed in multifunction
mode to service client devices and to provide WLAN intrusion monitoring. Intrusion detection information is gathered from the access points
Komentarze do niniejszej Instrukcji