Dell PowerConnect W-Airwave W-Airwave 7.2 Configuration Guide - Page 84

Profiles > IDS > Denial of Service > Rate Threshold, Denial of Service, IDS > Denial of Service

Page 84 highlights

Table 31 Profiles > IDS > Denial of Service Profile Settings (Continued) Field Default Description AP Flood Increase Time 3 Sets the time, in seconds, during which a configured number of Fake AP beacons must be received to trigger an alarm. AP Flood Detection 900 Quiet Time After an alarm has been triggered by a Fake AP flood, the time (in seconds) that must elapse before an identical alarm may be triggered. Detect EAP Rate No Enables or disables Extensible Authentication Protocol (EAP) handshake analysis to Anomaly detect an abnormal number of authentication procedures on a channel and generates an alarm when this condition is detected. EAP Rate Thresholds 60 Sets the number of EAP handshakes that must be received within the EAP Rate Time Interval to trigger an alarm. EAP Rate Time Interval 3 Sets the time, in seconds, during which the configured number of EAP handshakes must be received to trigger an alarm. EAP Rate Quiet Time 900 After an alarm has been triggered, sets the time (in seconds) that must elapse before another identical alarm may be triggered. Detect Rate Anomalies No Enables or disables detection of rate anomalies. Detect 802.11n 40MHz Yes Intolerance Setting Enables or disables detection of 802.11n 40 MHz intolerance setting, which controls whether stations and APs advertising 40 MHz intolerance will be reported. Client 40 MHz 900 Intolerance Detection Quiet Time Controls the quiet time (when to stop reporting intolerant STAs if they have not been detected), in seconds, for detection of 802.11n 40 MHz intolerance setting. 3. Select Add or Save. The added or edited Denial of Service profile appears on the IDS > Denial of Service profiles page. Profiles > IDS > Denial of Service > Rate Threshold The IDS rate threshold profile defines thresholds assigned to the different frame types for rate anomaly checking. A profile of this type is attached to each of the following 802.11 frame types in the IDS Denial of Service profile:  Association frames  Disassociation frames  Deauthentication frames  Probe Request frames  Probe Response frames  Authentication frames A channel threshold applies to an entire channel, while a node threshold applies to a particular client MAC address. Dell PowerConnect W provides predefined default IDS rate thresholds profiles for each of these types of frames. Default values depend upon the frame type. Perform these steps to create Rate Threshold Profiles for use with Denial of Service profiles. 1. Select Profiles > IDS > Denial of Service > Rate Thresholds in the Dell PowerConnect W Navigation pane. This page summarizes the current thresholds available. 84 | Dell PowerConnect W Configuration Reference Dell PowerConnect W AirWave 7.2 | Configuration Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160

84
|
Dell PowerConnect W Configuration Reference
Dell PowerConnect W AirWave 7.2
| Configuration Guide
3.
Select
Add
or
Save
.
The added or edited
Denial of Service
profile appears on the
IDS > Denial of Service
profiles page.
Profiles > IDS > Denial of Service > Rate Threshold
The IDS rate threshold profile defines thresholds assigned to the different frame types for rate anomaly checking.
A profile of this type is attached to each of the following 802.11 frame types in the IDS Denial of Service profile:
Association frames
Disassociation frames
Deauthentication frames
Probe Request frames
Probe Response frames
Authentication frames
A channel threshold applies to an entire channel, while a node threshold applies to a particular client MAC
address. Dell PowerConnect W provides predefined default IDS rate thresholds profiles for each of these types of
frames. Default values depend upon the frame type.
Perform these steps to create Rate Threshold Profiles for use with
Denial of Service
profiles.
1.
Select
Profiles > IDS > Denial of Service > Rate Thresholds
in the
Dell PowerConnect W Navigation
pane. This page summarizes the current thresholds available.
AP Flood Increase Time
3
Sets the time, in seconds, during which a configured number of Fake AP beacons must
be received to trigger an alarm.
AP Flood Detection
Quiet Time
900
After an alarm has been triggered by a Fake AP flood, the time (in seconds) that must
elapse before an identical alarm may be triggered.
Detect EAP Rate
Anomaly
No
Enables or disables Extensible Authentication Protocol (EAP) handshake analysis to
detect an abnormal number of authentication procedures on a channel and generates
an alarm when this condition is detected.
EAP Rate Thresholds
60
Sets the number of EAP handshakes that must be received within the EAP Rate Time
Interval to trigger an alarm.
EAP Rate Time Interval
3
Sets the time, in seconds, during which the configured number of EAP handshakes must
be received to trigger an alarm.
EAP Rate Quiet Time
900
After an alarm has been triggered, sets the time (in seconds) that must elapse before
another identical alarm may be triggered.
Detect Rate Anomalies
No
Enables or disables detection of rate anomalies.
Detect 802.11n 40MHz
Intolerance Setting
Yes
Enables or disables detection of 802.11n 40 MHz intolerance setting, which controls
whether stations and APs advertising 40 MHz intolerance will be reported.
Client 40 MHz
Intolerance Detection
Quiet Time
900
Controls the quiet time (when to stop reporting intolerant STAs if they have not been
detected), in seconds, for detection of 802.11n 40 MHz intolerance setting.
Table 31
Profiles > IDS > Denial of Service Profile Settings
(Continued)
Field
Default
Description