User's Guide

Table Of Contents
Alarms that started 24 to 72 hours ago
Alarms that started more than 72 hours ago.
Select the checkbox(es) for the alarm states and/or time ranges when the alarms started that you want
to display.
Alarm ID Filter
Use the Alarm ID to filter alarms using the alarm ID.
Normally, the alarm ID can be found in things such as:
an email that was generated by an alarm.
a SNMP notification generated by a Trap action defined in the Action Manager.
a report generated by the Report system.
Type or paste an alarm ID in the Alarm ID field to filter alarms using that alarm ID. Only the alarm
matching the ID will be displayed.
Alarm Categories and Criticality
AirDefense Services Platform generates alarms when certain events or conditions occur in your wireless
LAN that violate a policy or performance threshold.
To make alarms easy to identify, AirDefense groups alarms into nine categories, and assigns a criticality
to each alarm. Alarm notifications can also be delivered to the administrator via Email, SNMP, or Syslog.
Alarm Categories
The nine alarm categories are as follows:
Anomalous BehaviorDevices that operate outside of their normal behavior settings and generate
events that could indicate anomalous or suspicious activity.
ExploitsEvents caused by a potentially malicious user actively interacting on your Wireless LAN
using a laptop/PC as a wireless attack platform.
InfrastructureEvents that are generated based on the SNMP traps received from the infrastructure
devices.
PerformanceWireless LAN trac that exceeds set performance thresholds for devices.
Platform HealthEvents that provide information about the state of the AirDefense Services platform
and the Sensors which report back to the appliance.
Policy ComplianceWireless LAN trac that violates established or default policies for devices.
ReconnaissanceMonitors and tracks external devices that are attempting to monitor your Wireless
LAN.
Alarms
Alarm ID Filter
Extreme AirDefense User Guide for version 10.5. 489