05-Web configuration examples (AC+fit AP)

HomeSupportDoc SetsDoc PackagesH3C Wireless Products All-in-One-6W10005-Web configuration examples (AC+fit AP)
Table of Contents
Related Documents
42-Device Classification and Countermeasure Configuration Example

 

H3C Access Controllers

Comware 7 Device Classification and Countermeasure

Configuration Example

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Copyright © 2022 New H3C Technologies Co., Ltd. All rights reserved.

No part of this manual may be reproduced or transmitted in any form or by any means without prior written consent of New H3C Technologies Co., Ltd.

Except for the trademarks of New H3C Technologies Co., Ltd., any trademarks that may be mentioned in this document are the property of their respective owners.

The information in this document is subject to change without notice.



Overview

The following information provides an example for configuring device classification and countermeasures.

Prerequisites

The following information applies to Comware 7-based access controllers. Procedures and information in the examples might be slightly different depending on the software or hardware version of the H3C access controllers.

The configuration examples were created and verified in a lab environment, and all the devices were started with the factory default configuration. When you are working on a live network, make sure you understand the potential impact of every command on your network.

The following information is provided based on the assumption that you have basic knowledge of WIPS and WLAN access.

Example: Configuring device classification and countermeasure

Network configuration

As shown in Figure 1, the sensor connects to the AC through the switch. AP 1 and AP 2 provide wireless services to clients through SSID abc. Perform the following tasks:

·     Enable WIPS for the sensor.

·     Configure wireless device classification to add MAC address 000f-1c35-12a5 to the static prohibited device list and SSID abc to the trusted SSID list.

·     Configure countermeasures to enable WIPS to take countermeasures against potential-external APs and unauthorized clients.

Figure 1 Network diagram

 

 

Procedures

Configuring basic features on the AC

Configure wireless service, IP address, AP access, and radio settings. (Details not shown.)

Configuring a classification policy

1.     Click the Network View tab at the bottom of the page.

2.     From the navigation pane, select Wireless Configuration > Wireless Security.

3.     Click the Add button  to add a classification policy.

a.     Enter class1 in the Policy name field.

b.     Enter abc in the Trust SSID field.

c.     Enter 00-0f-1c-35-12-a5 in the Block MAC field.

d.     Click Apply.

Figure 2 Adding a classification policy

 

Configuring a countermeasure policy

1.     Click the Network View tab at the bottom of the page.

2.     From the navigation pane, select Wireless Configuration > Wireless Security.

3.     Click the Add button  to add a countermeasure policy.

a.     Enter protect in the Policy name field.

b.     Select Potential-external AP and Unauthorized client from the Categories list.

c.     Click Apply.

Figure 3 Adding a countermeasure policy

 

Configuring a VSD

1.     Click the Network View tab at the bottom of the page.

2.     From the navigation pane, select Wireless Configuration > Wireless Security.

3.     Click the Add button  to add a VSD.

a.     Enter VSD_1 in the VSD name field.

b.     Select class1 from the Classification policy list.

c.     Select protect from the Countermeasure policy list.

d.     Click Apply.

Figure 4 Adding a VSD

 

Enabling WIPS

1.     Click the Network View tab at the bottom of the page.

2.     From the navigation pane, select Wireless Configuration > Wireless Security.

3.     Click the More button  to enable WIPS.

a.     On the page that opens, select sensor and click the Edit button  to edit the sensor.

b.     On the page that opens, select a radio band from the Radio list and select a VSD from the VSD name list.

c.     Click Apply.

Figure 5 Enabling WIPS

 

Verifying the configuration

1.     Click the Network View tab at the bottom of the page.

2.     From the navigation pane, select Monitoring > Network Security, and view the relevant information shown in the Countermeasure Statistics area.

Related documentation

H3C Access Controllers Web-Based Configuration Guide

  • Cloud & AI
  • InterConnect
  • Intelligent Computing
  • Security
  • SMB Products
  • Intelligent Terminal Products
  • Product Support Services
  • Technical Service Solutions
All Services
  • Resource Center
  • Policy
  • Online Help
All Support
  • Become a Partner
  • Partner Resources
  • Partner Business Management
All Partners
  • Profile
  • News & Events
  • Online Exhibition Center
  • Contact Us
All About Us
新华三官网