
Dell PowerConnect W AirWave 7.2 |User Guide Configuring AWMS | 65
Enabling or Disabling PCI Auditing
Perform these steps to verify status and to enable or disable AWMS support for PCI 1.2 requirements. enabling
one or all PCI standards on AWMS enables real-time information and generated reports that advise on Pass or
Fail status. The PCI auditing supported in AWMS is reported in Table 35.
1. To determine what PCI Compliance standards are enabled or disabled on AWMS, navigate to the AMP
Setup > PCI Compliance page, illustrated in Figure 32.
Figure 32 AMP Setup > PCI Compliance Page Illustration
2. To enable, disable, or edit any category of PCI Compliance monitoring in AWMS, select the pencil icon next
to the category. The Default Credential Compliance page displays for the respective PCI standard.
2.1 Monitoring the presence of vendor-supplied default security settings
When Enabled: PCI Requirement 2 establishes the standard in which all vendor-supplied default
passwords are changed prior to a device’s presence and operation in the network.
A device fails requirement 2.1 if the username, passwords or SNMP credentials being used by AWMS
to communicate with the device are on a list of forbidden default credentials. The list includes common
vendor default passwords, for example.
When Disabled: device passwords and other vendor default settings are not checked for PCI
compliance.
2.1.1 Changing vendor-supplied defaults for wireless environments
When Enabled: A device fails requirement 2.1.1 if the passphrases, SSIDs, or other security-related
settings are on a list of forbidden values that AWMS establishes and tracks. The list includes common
vendor default passwords. The user can input new values to achieve compliance.
When Disabled: network devices are not checked for forbidden information and PCI Compliance is not
established.
4.1.1 Using strong encryption in wireless networks
When Enabled: PCI Requirement 4 establishes the standard by which payment cardholder data is
encrypted prior to transmission across open public networks. PCI disallows WEP encryption as an
approved encryption method after June 20, 2010. A device fails requirement 4.1.1 if the desired or actual
configuration reflect that WEP is enabled on the network, or if associated users can connect with WEP.
When Disabled: AWMS cannot establish a pass or fail status with regard to PCI encryption
requirements on the network.
11.4
Using intrusion-detection or intrusion-prevention systems to monitor all traffic
When Enabled: AWMS reports pass or fail status when monitoring devices capable of reporting IDS
events. Recent IDS events are summarized in the PCI Compliance report or the IDS Report.
When Disabled: AWMS does not monitor the presence of PCI-compliant intrusion detection or
prevention systems, nor can it report
Pass or Fail status with regard to IDS events.
Table 35 PCI Requirements and Support in AWMS (Continued)
Requirement Description
Comentarios a estos manuales