Users Guide

Table Of Contents
Dell PowerConnect ArubaOS 5.0 | User Guide Wireless Intrusion Prevention | 47 1
detect-ap-flood
detect-eap-rate-anomaly
detect-ht-40mhz-intolerance
detect-rate-anomalies
disassoc-rate-thresholds <number>
eap-rate-quiet-time <seconds>
eap-rate-threshold <number>
eap-rate-time-interval <seconds>
probe-request-rate-thresholds <number>
probe-response-rate-thresholds <number>
spoofed-deauth-blacklist
IDS Rate Thresholds Profile
IDS rate threshold profile defines thresholds assigned to the different frame types for rate anomaly checking. A
profile of this type is attached to each of the following 802.11 frame types in the IDS Denial of Service profile:
z Association frames
z Disassociation frames
z Deauthentication frames
z Probe Request frames
z Probe Response frames
z Authentication frames
A channel threshold applies to an entire channel, while a node threshold applies to a particular client MAC
address. Dell provides predefined default IDS rate thresholds profiles for each of these types of frames. Default
values depend upon the frame type.
Table 94 describes the parameters you can configure for the IDS rate threshold profile.
Configuring the Rate Threshold Profile via the WebUI
1. In the Profiles list, under the IDS DoS profile, select the IDS rate threshold profile you want to configure, or
enter the name of a new profile in the entry blank then click add.
2. Modify parameters described in Table 94.
3. Click Apply to save your changes to the selected profile, or, to create a new IDS rate threshold profile, click
Save As, enter a new profile name, then click Apply.
Table 94 IDS Rate Thresholds Profile Configuration Parameters
Parameter Description
Channel Increase Time Time, in seconds, in which the threshold must be exceeded in order to trigger an alarm.
Channel Quiet Time After an alarm has been triggered, the time that must elapse before another identical
alarm may be triggered. This option prevents excessive messages in the log file.
Channel Threshold Specifies the number of a specific type of frame that must be exceeded within a specific
interval in an entire channel to trigger an alarm.
Node Quiet Time After an alarm has been triggered, the time that must elapse before another identical
alarm may be triggered. This option prevents excessive messages in the log file.
Node Threshold Specifies the number of a specific type of frame that must be exceeded within a specific
interval for a particular client MAC address to trigger an alarm.
Node Time Interval Time, in seconds, in which the threshold must be exceeded in order to trigger an alarm.