Dell PowerConnect W-Airwave W-Airwave 7.2 Configuration Guide - Page 83

Profiles > IDS > Denial of Service, Dell PowerConnect W Navigation, Signature Matching, pencil

Page 83 highlights

1. Select Profiles > IDS > Denial of Service in the Dell PowerConnect W Navigation pane. 2. Select the Add button to create a new Signature Matching profile, or click the pencil icon next to an existing profile to edit. The Details page appears. Complete the settings as described in Table 31: Table 31 Profiles > IDS > Denial of Service Profile Settings Field Default Description General Settings Folder Top Name Blank Referenced Profiles Rate Thresholds for Assoc Frames default Rate Thresholds for Disassoc Frames default Rate Thresholds for Deauth Frames default Rate Thresholds for default Probe Request Frames Rate Thresholds for Probe Response Frames default Rate Thresholds for Auth Frames default Other Settings Detect Disconnect Yes Station Attack Disconnect STA 900 Detection Quiet Time Spoofed Deauth No Blacklist Detect AP Flood Attack No AP Flood Threshold 50 Set the folder with which the profile is associated. The drop-down menu displays all folders available for association with the profile. Enter the name of the profile. Select a profile from the drop-down menu, or click the edit (icon) or add (icon) to edit or create a profile that sets the rate threshold for association frames. The IDS rate threshold profile defines thresholds assigned to the different frame types for rate anomaly checking. Select a profile from the drop-down menu, or click the edit (icon) or add (icon) to edit or create a profile that sets the rate threshold for disassociation frames. The IDS rate threshold profile defines thresholds assigned to the different frame types for rate anomaly checking. Select a profile from the drop-down menu, or click the edit (icon) or add (icon) to edit or create a profile that sets the rate threshold for de-authentication frames. The IDS rate threshold profile defines thresholds assigned to the different frame types for rate anomaly checking. Select a profile from the drop-down menu, or click the edit (icon) or add (icon) to edit or create a profile that sets the rate threshold for probe request frames. The IDS rate threshold profile defines thresholds assigned to the different frame types for rate anomaly checking. Select a profile from the drop-down menu, or click the edit (icon) or add (icon) to edit or create a profile that sets the rate threshold for probe response frames. The IDS rate threshold profile defines thresholds assigned to the different frame types for rate anomaly checking. Select a profile from the drop-down menu, or click the edit (icon) or add (icon) to edit or create a profile that sets the rate threshold for authentication frames. The IDS rate threshold profile defines thresholds assigned to the different frame types for rate anomaly checking. Enables or disables detection of station disconnection attacks. After a station disconnection attack is detected, sets the time (in seconds) that must elapse before another identical alarm can be generated. Enables or disables automatic client blacklisting of spoofed de-authentication. Enables or disables the detection of flooding with fake AP beacons to confuse legitimate users and to increase the amount of processing need on client operating systems. Sets the number of Fake AP beacons that must be received within the Flood Increase Time to trigger an alarm. Dell PowerConnect W AirWave 7.2 | Configuration Guide Dell PowerConnect W Configuration Reference | 83

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160

Dell PowerConnect W AirWave 7.2
| Configuration Guide
Dell PowerConnect W Configuration Reference
|
83
1.
Select
Profiles > IDS > Denial of Service
in the
Dell PowerConnect W Navigation
pane.
2.
Select the
Add
button to create a new
Signature Matching
profile, or click the
pencil
icon next to an existing
profile to edit. The
Details
page appears. Complete the settings as described in
Table 31
:
Table 31
Profiles > IDS > Denial of Service Profile Settings
Field
Default
Description
General Settings
Folder
Top
Set the folder with which the profile is associated. The drop-down menu displays all
folders available for association with the profile.
Name
Blank
Enter the name of the profile.
Referenced Profiles
Rate Thresholds for
Assoc Frames
default
Select a profile from the drop-down menu, or click the edit (icon) or add (icon) to edit or
create a profile that sets the rate threshold for association frames. The IDS rate
threshold profile defines thresholds assigned to the different frame types for rate
anomaly checking.
Rate Thresholds for
Disassoc Frames
default
Select a profile from the drop-down menu, or click the edit (icon) or add (icon) to edit or
create a profile that sets the rate threshold for disassociation frames. The IDS rate
threshold profile defines thresholds assigned to the different frame types for rate
anomaly checking.
Rate Thresholds for
Deauth Frames
default
Select a profile from the drop-down menu, or click the edit (icon) or add (icon) to edit or
create a profile that sets the rate threshold for de-authentication frames. The IDS rate
threshold profile defines thresholds assigned to the different frame types for rate
anomaly checking.
Rate Thresholds for
Probe Request Frames
default
Select a profile from the drop-down menu, or click the edit (icon) or add (icon) to edit or
create a profile that sets the rate threshold for probe request frames. The IDS rate
threshold profile defines thresholds assigned to the different frame types for rate
anomaly checking.
Rate Thresholds for
Probe Response
Frames
default
Select a profile from the drop-down menu, or click the edit (icon) or add (icon) to edit or
create a profile that sets the rate threshold for probe response frames. The IDS rate
threshold profile defines thresholds assigned to the different frame types for rate
anomaly checking.
Rate Thresholds for
Auth Frames
default
Select a profile from the drop-down menu, or click the edit (icon) or add (icon) to edit or
create a profile that sets the rate threshold for authentication frames. The IDS rate
threshold profile defines thresholds assigned to the different frame types for rate
anomaly checking.
Other Settings
Detect Disconnect
Station Attack
Yes
Enables or disables detection of station disconnection attacks.
Disconnect STA
Detection Quiet Time
900
After a station disconnection attack is detected, sets the time (in seconds) that must
elapse before another identical alarm can be generated.
Spoofed Deauth
Blacklist
No
Enables or disables automatic client blacklisting of spoofed de-authentication.
Detect AP Flood Attack
No
Enables or disables the detection of flooding with fake AP beacons to confuse legitimate
users and to increase the amount of processing need on client operating systems.
AP Flood Threshold
50
Sets the number of Fake AP beacons that must be received within the Flood Increase
Time to trigger an alarm.