Users Guide

Table Of Contents
472 | Wireless Intrusion Prevention Dell PowerConnect ArubaOS 5.0 | [User Guide
Configuring the Rate Thresholds Profile via the CLI
To configure this profile via the command-line interface, access the CLI in config mode and issue the following
commands:
ids rate-thresholds-profile <name>
channel-inc-time <seconds>
channel-quiet-time <seconds>
clone <profile>
node-quiet-time <seconds>
node-threshold <number>
node-time-interval <seconds>
ids dos-profile <profile>
<frame-type> <thresholds-profile>
Impersonation Detection Profile
Table 95 describes the parameters you can configure in the IDS Impersonation profile.
Configuring the Impersonation Profile via the WebUI
1. Navigate to the Configuration > AP Configuration page. Select either AP Group or AP Specific.
If you selected AP Group, click Edit for the AP group name for which you want to configure IDS.
If you selected AP Specific, select the name of the AP for which you want to configure IDS.
2. Expand the IDS menu. Select IDS profile to display the IDS profiles that are contained in the top-level
profile.
3. Select IDS Impersonation profile.
4. You can select a predefined profile from the drop-down menu. Or you can modify parameters and click Save
As to create an IDS impersonation profile instance.
5. Click Apply.
Table 95 IDS Impersonation Profile Configuration Parameters
Parameter Description
Detect AP Impersonation Enables or disables detection of AP impersonation. In AP impersonation attacks, the
attacker sets up an AP that assumes the BSSID and ESSID of a valid AP. AP
impersonation attacks can be done for man-in-the-middle attacks, a rogue AP attempting
to bypass detection, or a honeypot attack.
Default: enabled
Protect from AP Impersonation When AP impersonation is detected, both the legitimate and impersonating AP are
disabled using a denial of service attack.
Default: disabled
Beacon Diff Threshold Percentage increase in beacon rate that triggers an AP impersonation event.
Default: 50%
Beacon Increase Wait Time Time, in seconds, after the Beacon Diff Threshold is crossed before an AP impersonation
event is generated.
Default: 3 seconds
Note: If you selected a predefined IDS profile, you cannot select or create a different IDS impersonation profile instance. You can
modify parameters within the IDS impersonation profile instance.