User's Manual
Parameter Description
Default: enabled
Mark Neighbor APs as Persistent
Neighbor APs
Enables or disables APs that are marked as neighbor from being
aged out.
Default: enabled
Learn APs Enables or disables AP learning. Learning affects the way APs
are classified.
Default: disabled
In the CLI
Use the following commands to configure WMS via the CLI. The parameters in this command are described in
detail in Table 90.
ids wms-general-profile
adhoc-ap-ageout-interval <minutes> | ap-ageout-interval <minutes> | collect-stats
{disable|enable} | learn-ap {enable|disable} | learn-system-wired-macs |
persistent-neighbor {enable|disable} | poll-interval <milliseconds> |
poll-retries <number> | propagate-wired-macs {enable|disable} | sta-ageout-interval
<minutes> | stat-update {enable|disable}
Configuring Local WMS Settings
You can also use the CLI to define local WMS system settings for the maximum number of APs and client
stations.
Use this command with caution. Increasing the limit will cause an increase in usage in the memory by WMS. In
general, each entry will consume about 500 bytes of memory. If the setting is bumped up by 2000, then it will cause
an increase in WMS memory usage by 1MB
(host) (config) #ids wms-local-system-profile max-threshold <max-threshold>
Managing the WMS Database
The WMS process interacts with all the air monitor (AM) processes in the network. When WMS receives an
event message from an AM, the WMS process will save the event information along with the BSSID of the AP
that generated the event in the WMS database. Use the following commands in Enable mode to manage the
WMS database.
The wms export-db command exports the specified file as an ASCII text file into the WMS database.
(host) #wms export-db database <file>
The wms import-db command imports the specified file into the WMS database:
(host) #wms import-db database <file>
The wms reint-db command reinitializes the WMS database. Note that this command does not make an
automatic backup of the current database.
(host) #wms reint-db
Understanding Client Blacklisting
When a client is blacklisted in the Dell system, the client is not allowed to associate with any AP in the network
for a specified amount of time. If a client is connected to the network when it is blacklisted, a deauthentication
message is sent to force the client to disconnect. While blacklisted, the client cannot associate with another
SSID in the network.
Dell Networking W-Series ArubaOS 6.4.x | User Guide Wireless Intrusion Prevention | 476