Users Guide

Table Of Contents
Dell PowerConnect ArubaOS 5.0 | User Guide Wireless Intrusion Prevention | 46 9
There are four predefined DoS profiles, each of which provides different levels of detection and containment.
Table 93 describes the settings for each of the predefined profiles:
AP Flood Increase Time Time, in seconds, during which a configured number of Fake AP beacons must be
received to trigger an alarm.
Default: 3 seconds
AP Flood Detection Quiet Time After an alarm has been triggered by a Fake AP flood, the time (in seconds) that must
elapse before an identical alarm may be triggered.
Default: 900 seconds
Detect EAP Rate Anomaly Enables or disables Extensible Authentication Protocol (EAP) handshake analysis to
detect an abnormal number of authentication procedures on a channel and generates an
alarm when this condition is detected.
Default: disabled
EAP Rate Threshold Number of EAP handshakes that must be received within the EAP Rate Time Interval to
trigger an alarm.
Default: 60
EAP Rate Time Interval Time, in seconds, during which the configured number of EAP handshakes must be
received to trigger an alarm.
Default: 3 seconds
EAP Rate Quiet Time After an alarm has been triggered, the time (in seconds) that must elapse before another
identical alarm may be triggered.
Default: 900 seconds
Detect Rate Anomalies Enables or disables detection of rate anomalies.
Default: disabled
Detect 802.11n 40Mhz Intolerance
Setting
Enables or disables detection of 802.11n 40 MHz intolerance setting, which controls
whether stations and APs advertising 40 MHz intolerance will be reported.
Default: enabled
Client 40MHz Intolerance Detection
Quiet Time
Controls the quiet time (when to stop reporting intolerant STAs if they have not been
detected), in seconds, for detection of 802.11n 40 MHz intolerance setting.
Default: 900 seconds
Table 93 Predefined IDS DoS Profiles
Parameter
ids-dos-
disabled
ids-dos-low-
setting
ids-dos-
medium-setting
ids-dos-high-
setting
Detect Disconnect Station Attack disabled enabled enabled disabled
Disconnect STA Detection Quiet Time 900 seconds 900 seconds 900 seconds 900 seconds
Spoofed Deauth Blacklist disabled disabled disabled disabled
Detect AP Flood Attack disabled disabled disabled disabled
AP Flood Threshold 50 50 50 50
AP Flood Increase Time 3 seconds 3 seconds 3 seconds 3 seconds
AP Flood Detection Quiet Time 900 seconds 900 seconds 900 seconds 900 seconds
Detect EAP Rate Anomaly disabled disabled enabled enabled
EAP Rate Threshold 60 60 30 60
EAP Rate Time Interval 3 seconds 3 seconds 3 seconds 3 seconds
Table 92 IDS Denial of Service Profile Configuration Parameters (Continued)
Parameter Description