Users Guide

Table Of Contents
466 | Wireless Intrusion Prevention Dell PowerConnect ArubaOS 5.0 | [User Guide
Signature Detection
Many WLAN intrusion and attack tools generate characteristic signatures that can be detected by the Dell
network. The system is pre-configured with several known signatures, and also includes the ability for you to
create new signatures. For more details on how to configure and create new signatures refer to “Signature
Detection” on page 466.
IDS Configuration
This section describes how to configure IDS features using the IDS profiles. You apply the top-level IDS profile
to an AP group or specific AP.
IDS Profile Hierarchy
The top-level IDS profile, assigned to an AP group or AP name, refers to the following IDS profiles:
ArubaOS includes predefined top-level IDS profiles that provide different levels of sensitivity. The following are
predefined IDS profiles:
z ids-disabled
z ids-high-setting
z ids-low-setting (the default setting)
z ids-medium-setting
Configuring IDS via the WebUI
1. Navigate to the Configuration > AP Configuration page. Select either AP Group or AP Specific.
If you selected AP Group, click Edit for the AP group name for which you want to configure IDS.
If you selected AP Specific, select the name of the AP for which you want to configure IDS.
2. In the Profiles list, expand the IDS menu. Select IDS profile to display the IDS profiles that are contained in
the top-level profile. You can select a predefined IDS profile or create a new profile.
3. Click Apply.
Table 89 IDS Profiles
Profile Description
IDS General profile Configures AP attributes.
IDS Rate Thresholds profile Defines thresholds assigned to the different frame types for rate anomaly checking.
IDS Signature Matching Configures signatures for intrusion detection. This profile can include predefined
signatures or signatures that you configure.
IDS DoS profile Configures traffic anomalies for Denial of Service attacks.
IDS Impersonation profile Configures anomalies for impersonation attacks.
IDS Unauthorized Device profile Configures detection for unauthorized devices. Also configures rogue AP detection and
containment.
Note: A predefined IDS profile refers to specific instances of the other IDS profiles. You cannot create new instances of a profile
within a predefined IDS profile. You can modify parameters within the other IDS profiles.