Dell PowerConnect W-Airwave W-Airwave 7.2 Configuration Guide - Page 80

Profiles > IDS > Signature Matching, General, IDS > General, Signature Matching

Page 80 highlights

Table 27 Profiles > IDS > General Profile Settings (Continued) Field Default Description Wireless Containment Deauth only Debug Wireless No Containment Wired Containment No Wired Containment of No AP's Adj MACs Monitored Device Stats 0 Update Interval (0-36000 sec) Mobility Manager RTLS No Send Ad-hoc Info to Yes Controller Ad-hoc AP Max Unseen 180 Timeout (5-36000 sec) Enable wireless containment including Tarpit Shielding. Tarpit shielding works by steering a client to a tarpit so that the client associates with it instead of the AP that is being contained.  deauth-only-Containment using deauthentication only  none-Disable wireless containment  tarpit-all-sta-Wireless containment by tarpit of all stations  tarpit-non-valid-sta-Wireless containment by tarpit of non-valid clients NOTE: Tarpit requires a minimum version of 6.0.0.0. Enable/disable debug of containment from the wireless side. Note: Enabling this debug option will cause containment to not function properly. Enable containment from the wired side. Enable/disable wired containment of MACs offset by one from APs BSSID. NOTE: This setting requires a minimum of AOS 6.0.0.0. Time interval, in seconds, for AP to update the switch with stats for monitored devices. Minimum is 60. Enable/disable RTLS communication with the configured mobility-manager Enable or disable sending Ad hoc information to the controller from the AP. NOTE: This setting requires a WIPS or RFprotect license and a minimum of AOS 6.0.0.0. Ageout time in seconds since ad hoc (IBSS) AP was last seen. NOTE: This setting requires a minimum of AOS 6.0.0.0. Ad-hoc (IBSS) AP 5 Inactivity Timeout (5- 36000 sec) Ad hoc (IBSS) AP inactivity timeout in number of scans. NOTE: This setting requires a minimum of AOS 6.0.0.0. IDS Event Generation on None AP Enable or disable IDS event generation from the AP. Event generation from the AP can be enabled for syslogs, traps, or both. This does not affect generation of IDS correlated events on the switch. 3. Select Add or Save. The added or edited General profile appears on the IDS > General profiles page. Profiles > IDS > Signature Matching The IDS signature matching profile contains signatures for intrusion detection. This profile can include predefined or custom signatures. Table 28 describes the predefined signatures that you can add to the profile. Perform these steps to configure a Signature Matching profile. 1. Select Profiles > IDS > Signature Matching in the Dell PowerConnect W Navigation pane. 2. Select the Add button to create a new Signature Matching profile, or click the pencil icon next to an existing profile to edit. The Details page appears. Complete the settings as described in Table 28: Table 28 Profiles > IDS > Signature Matching Profile Settings Field Default Description General Settings Folder Top Set the folder with which the profile is associated. The drop-down menu displays all folders available for association with the profile. 80 | Dell PowerConnect W Configuration Reference Dell PowerConnect W AirWave 7.2 | Configuration Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160

80
|
Dell PowerConnect W Configuration Reference
Dell PowerConnect W AirWave 7.2
| Configuration Guide
3.
Select
Add
or
Save
.
The added or edited
General
profile appears on the
IDS > General
profiles page.
Profiles > IDS > Signature Matching
The IDS signature matching profile contains signatures for intrusion detection. This profile can include predefined
or custom signatures.
Table 28
describes the predefined signatures that you can add to the profile.
Perform these steps to configure a
Signature Matching
profile.
1.
Select
Profiles > IDS > Signature Matching
in the
Dell PowerConnect W Navigation
pane.
2.
Select the
Add
button to create a new
Signature Matching
profile, or click the
pencil
icon next to an existing
profile to edit. The
Details
page appears. Complete the settings as described in
Table 28
:
Wireless Containment
Deauth
only
Enable wireless containment including Tarpit Shielding. Tarpit shielding works by
steering a client to a tarpit so that the client associates with it instead of the AP that is
being contained.
deauth-only
—Containment using deauthentication only
none
—Disable wireless containment
tarpit-all-sta
—Wireless containment by tarpit of all stations
tarpit-non-valid-sta
—Wireless containment by tarpit of non-valid clients
NOTE:
Tarpit requires a minimum version of 6.0.0.0.
Debug Wireless
Containment
No
Enable/disable debug of containment from the wireless side.
Note
: Enabling this debug option will cause containment to
not
function properly.
Wired Containment
No
Enable containment from the wired side.
Wired Containment of
AP's Adj MACs
No
Enable/disable wired containment of MACs offset by one from APs BSSID.
NOTE:
This setting requires a minimum of AOS 6.0.0.0.
Monitored Device Stats
Update Interval
(0-36000
sec)
0
Time interval, in seconds, for AP to update the switch with stats for monitored devices.
Minimum is 60.
Mobility Manager RTLS
No
Enable/disable RTLS communication with the configured mobility-manager
Send Ad-hoc Info to
Controller
Yes
Enable or disable sending Ad hoc information to the controller from the AP.
NOTE:
This setting requires a WIPS or RFprotect license and a minimum of AOS 6.0.0.0.
Ad-hoc AP Max Unseen
Timeout
(5-36000 sec)
180
Ageout time in seconds since ad hoc (IBSS) AP was last seen.
NOTE:
This setting requires a minimum of AOS 6.0.0.0.
Ad-hoc (IBSS) AP
Inactivity Timeout
(5-
36000 sec)
5
Ad hoc (IBSS) AP inactivity timeout in number of scans.
NOTE:
This setting requires a minimum of AOS 6.0.0.0.
IDS Event Generation on
AP
None
Enable or disable IDS event generation from the AP. Event generation from the AP can
be enabled for syslogs, traps, or both. This does not affect generation of IDS correlated
events on the switch.
Table 28
Profiles > IDS > Signature Matching Profile Settings
Field
Default
Description
General Settings
Folder
Top
Set the folder with which the profile is associated. The drop-down menu displays
all folders available for association with the profile.
Table 27
Profiles > IDS > General Profile Settings
(Continued)
Field
Default
Description