Dell PowerConnect W-Airwave W-Airwave 7.2 Configuration Guide - Page 82

Parameter, ids-dosdisabled, ids-dos-lowsetting, Profiles, > IDS > Denial of Service

Page 82 highlights

client from the Dell PowerConnect W system. When a client is blacklisted in the Dell PowerConnect W system, the client is not allowed to associate with any AP in the network for a specified amount of time. If a client is connected to the network when it is blacklisted, a de-authentication message is sent to force the client to disconnect. While blacklisted, the client cannot associate with another SSID in the network. Table 30 summarizes the predefined IDS Denial of Service profiles. These profiles are viewable with the Profiles > IDS > Denial of Service path in the navigation pane. Table 30 Predefined IDS DoS Profiles Parameter ids-dosdisabled ids-dos-lowsetting ids-dosmedium-setting ids-dos-highsetting Detect Disconnect Station Attack disabled enabled enabled Disconnect STA Detection Quiet Time 900 seconds 900 seconds 900 seconds Spoofed Deauth Blacklist disabled disabled disabled Detect AP Flood Attack disabled disabled disabled AP Flood Threshold 50 50 50 AP Flood Increase Time 3 seconds 3 seconds 3 seconds AP Flood Detection Quiet Time 900 seconds 900 seconds 900 seconds Detect EAP Rate Anomaly disabled disabled enabled EAP Rate Threshold 60 60 30 EAP Rate Time Interval 3 seconds 3 seconds 3 seconds EAP Rate Quiet Time 900 seconds 900 seconds 900 seconds Detect Rate Anomalies disabled disabled disabled Detect 802.11n 40 MHz Intolerance Setting disabled enabled enabled Client 40 MHz Intolerance Detection Quiet Time 900 seconds 900 seconds 900 seconds Rate Thresholds for Assoc Frames default default default Rate Thresholds for Disassoc default Frames default default Rate Thresholds for Deauth Frames default default default Rate Thresholds for Probe Request Frames default probe-request-response- probe-request-response- thresholds thresholds Rate Thresholds for Probe Response Frames default probe-request- probe-request-response- probe-request-response- response-thresholds thresholds thresholds default default default default enabled 900 seconds disabled disabled 50 3 seconds 900 seconds enabled 60 3 seconds 900 seconds enabled enabled 900 seconds default default default probe-request-responsethresholds Rate Thresholds for Auth Frames Perform these steps to configure or edit an IDS Denial of Service profile, and to create or edit profiles that are referenced by a DOC profile. 82 | Dell PowerConnect W Configuration Reference Dell PowerConnect W AirWave 7.2 | Configuration Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160

82
|
Dell PowerConnect W Configuration Reference
Dell PowerConnect W AirWave 7.2
| Configuration Guide
client from the Dell PowerConnect W system. When a client is blacklisted in the Dell PowerConnect W system,
the client is not allowed to associate with any AP in the network for a specified amount of time. If a client is
connected to the network when it is blacklisted, a de-authentication message is sent to force the client to
disconnect. While blacklisted, the client cannot associate with another SSID in the network.
Table 30
summarizes the predefined IDS Denial of Service profiles. These profiles are viewable with the
Profiles
> IDS > Denial of Service
path in the navigation pane.
Perform these steps to configure or edit an IDS
Denial of Service
profile, and to create or edit profiles that are
referenced by a DOC profile.
Table 30
Predefined IDS DoS Profiles
Parameter
ids-dosdisabled
ids-dos-lowsetting
ids-dosmedium-setting
ids-dos-highsetting
Detect Disconnect Station
Attack
disabled
enabled
enabled
enabled
Disconnect STA Detection
Quiet Time
900 seconds
900 seconds
900 seconds
900 seconds
Spoofed Deauth Blacklist
disabled
disabled
disabled
disabled
Detect AP Flood Attack
disabled
disabled
disabled
disabled
AP Flood Threshold
50
50
50
50
AP Flood Increase Time
3 seconds
3 seconds
3 seconds
3 seconds
AP Flood Detection Quiet Time
900 seconds
900 seconds
900 seconds
900 seconds
Detect EAP Rate Anomaly
disabled
disabled
enabled
enabled
EAP Rate Threshold
60
60
30
60
EAP Rate Time Interval
3 seconds
3 seconds
3 seconds
3 seconds
EAP Rate Quiet Time
900 seconds
900 seconds
900 seconds
900 seconds
Detect Rate Anomalies
disabled
disabled
disabled
enabled
Detect 802.11n 40 MHz
Intolerance Setting
disabled
enabled
enabled
enabled
Client 40 MHz Intolerance
Detection Quiet Time
900 seconds
900 seconds
900 seconds
900 seconds
Rate Thresholds for Assoc
Frames
default
default
default
default
Rate Thresholds for Disassoc
Frames
default
default
default
default
Rate Thresholds for Deauth
Frames
default
default
default
default
Rate Thresholds for Probe
Request Frames
default
probe-request-response-
thresholds
probe-request-response-
thresholds
probe-request-response-
thresholds
Rate Thresholds for Probe
Response Frames
default probe-request-
response-thresholds
probe-request-response-
thresholds
probe-request-response-
thresholds
Rate Thresholds for Auth
Frames
default
default
default
default