Reference Guide
Table Of Contents
- Dell PowerConnect ArubaOS 5.0 Command Line Interface
- Introduction
- aaa authentication captive-portal
- aaa authentication dot1x
- aaa authentication mac
- aaa authentication mgmt
- aaa authentication stateful-dot1x
- aaa authentication stateful-dot1x clear
- aaa authentication stateful-ntlm
- aaa authentication via auth-profile
- aaa authentication via connection-profile
- aaa authentication via web-auth
- aaa authentication vpn
- aaa authentication wired
- aaa authentication wispr
- aaa authentication-server internal
- aaa authentication-server ldap
- aaa authentication-server radius
- aaa authentication-server tacacs
- aaa authentication-server windows
- aaa bandwidth-contract
- aaa derivation-rules
- aaa inservice
- aaa ipv6 user add
- aaa ipv6 user clear-sessions
- aaa ipv6 user delete
- aaa ipv6 user logout
- aaa password-policy mgmt
- aaa profile
- aaa query-server
- aaa radius-attributes
- aaa rfc-3576-server
- aaa server-group
- aaa sygate-on-demand
- aaa tacacs-accounting
- aaa test-server
- aaa timers
- aaa trusted-ap
- aaa user add
- aaa user clear-sessions
- aaa user delete
- aaa user fast-age
- aaa user logout
- aaa xml-api
- acceleration
- adp
- am
- ap authorization-profile
- ap enet-link-profile
- ap mesh-cluster-profile
- ap mesh-ht-ssid-profile
- ap mesh-radio-profile
- ap provisioning-profile
- ap regulatory-domain-profile
- ap snmp-profile (deprecated)
- ap snmp-user-profile (deprecated)
- ap system-profile
- ap wipe out flash
- ap wired-ap-profile
- ap wired-port-profile
- ap-group
- ap-regroup
- ap-rename
- ap-name
- apboot
- apflash
- apconnect
- apdisconnect
- arp
- audit-trail
- backup
- banner motd
- boot
- cellular profile
- clear
- clock set
- clock summer-time recurring
- clock timezone
- configure terminal
- controller-ip
- control-plane-security
- copy
- cp-bandwidth-contract
- crypto dynamic-map
- crypto ipsec
- crypto isakmp
- crypto isakmp policy
- crypto map global-map
- crypto pki
- crypto pki-import
- crypto-local ipsec-map
- crypto-local isakmp ca-certificate
- crypto-local isakmp dpd
- crypto-local isakmp key
- crypto-local isakmp permit-invalid-cert
- crypto-local isakmp server-certificate
- crypto-local isakmp xauth
- crypto-local pki
- database synchronize
- delete
- destination
- dialer
- dir
- dynamic-ip
- enable
- enable secret
- encrypt
- esi group
- esi parser domain
- esi parser rule
- esi parser rule-test
- esi ping
- esi server
- exit
- export
- firewall
- firewall cp
- firewall cp-bandwidth-contract
- gateway health-check disable
- guest-access-email
- halt
- help
- hostname
- ids dos-profile
- ids general-profile
- ids impersonation-profile
- ids profile
- ids rate-thresholds-profile
- ids signature-matching-profile
- ids signature-profile
- ids unauthorized-device-profile
- interface fastethernet | gigabitethernet
- interface loopback
- interface port-channel
- interface range
- interface tunnel
- interface vlan
- interface vlan ip igmp proxy
- ip access-list eth
- ip access-list extended
- ip access-list mac
- ip access-list session
- ip access-list standard
- ip cp-redirect-address
- ip default-gateway
- ip dhcp excluded-address
- ip dhcp pool
- ip domain lookup
- ip domain-name
- ip igmp
- ip local
- ip mobile active-domain
- ip mobile domain
- ip mobile foreign-agent
- ip mobile home-agent
- ip mobile proxy
- ip mobile revocation
- ip mobile trail
- ip name-server
- ip nat
- ip ospf
- ip pppoe-max-segment-size
- ip pppoe-password
- ip pppoe-service-name
- ip pppoe-username
- ip radius
- ip route
- ipv6 access-list session
- ipv6 firewall
- lacp group
- lacp port-priority
- lacp system-priority
- lacp timeout
- license
- localip
- local-userdb add
- local-userdb del
- local-userdb export
- local-userdb fix-database
- local-userdb import
- local-userdb maximum-expiration
- local-userdb modify
- local-userdb send-to-guest
- local-userdb send-to-sponsor
- local-userdb-guest add
- local-userdb-guest del
- local-userdb-guest modify
- local-userdb-guest send-email
- location
- logging
- logging facility
- logging level
- loginsession
- logout
- mac-address-table
- masterip
- master-redundancy
- mgmt-server
- mgmt-user
- mux-address
- mux-loop-prevention
- netdestination
- netservice
- network-printer
- network-storage
- ntp server
- packet-capture
- packet-capture-defaults
- page
- paging
- panic
- papi-security
- pcap
- ping
- pkt-trace
- pkt-trace-global
- pptp ip local pool
- priority-map
- process monitor
- prompt
- provision-ap
- rap-wml
- rap-wml table
- reload
- rename
- restore
- rf arm-profile
- rf dot11a-radio-profile
- rf dot11g-radio-profile
- rf event-thresholds-profile
- rf ht-radio-profile
- rf optimization-profile
- rft
- router mobile
- router ospf
- service
- show aaa authentication all
- show aaa authentication captive-portal
- show aaa authentication captive-portal customization
- show aaa authentication dot1x
- show aaa authentication mac
- show aaa authentication mgmt
- show aaa authentication stateful-dot1x
- show aaa authentication stateful-ntlm
- show aaa authentication via auth-profile
- show aaa authentication via connection-profile
- show aaa authentication via web-auth
- show aaa authentication vpn
- show aaa authentication wired
- show aaa authentication wispr
- show aaa authentication-server all
- show aaa authentication-server internal
- show aaa authentication-server ldap
- show aaa authentication-server radius
- show aaa authentication-server tacacs
- show aaa authentication-server windows
- show aaa tacacs-accounting
- show aaa bandwidth-contracts
- show aaa derivation-rules
- show aaa main-profile
- show aaa password-policy mgmt
- show aaa profile
- show aaa radius-attributes
- show aaa rfc-3576-server
- show aaa server-group
- show aaa state ap-group
- show aaa state configuration
- show aaa state debug-statistics
- show aaa state messages
- show aaa state mux-tunnel
- show aaa state station
- show aaa state user
- show aaa sygate-on-demand (deprecated)
- show aaa tacacs-accounting
- show aaa timers
- show aaa xml-api server
- show aaa web admin-port
- show aaa xml-api statistics
- show acceleration
- show acl ace-table
- show acl acl-table
- show acl hits
- show adp config
- show adp counters
- show ap active
- show ap allowed-channels
- show ap ap-group
- show ap arm history
- show ap arm neighbors
- show ap arm rf-summary
- show ap arm scan-times
- show ap arm state
- show ap association
- show ap association remote
- show ap authorization-profile
- show ap blacklist-clients
- show ap bss-table
- show ap bw-report
- show ap client status
- show ap config
- show ap coverage-holes
- show ap database
- show ap database-summary
- show ap debug association-failure
- show ap debug bss-config
- show ap debug bss-stats
- show ap debug client-mgmt-counters
- show ap debug client-stats
- show ap debug client-table
- show ap debug counters
- show ap debug datapath
- show ap debug driver-log
- show ap debug log
- show ap debug mgmt-frames (deprecated)
- show ap debug radio-stats
- show ap debug received-config
- show ap debug remote association
- show ap debug shaping-table
- show ap debug system-status
- show ap debug trace-addr
- show ap details
- show ap enet-link-profile
- show ap essid
- show ap ht-rates
- show ap image version
- show ap license-usage
- show ap load-balancing
- show ap mesh active
- show ap mesh debug counters
- show ap mesh debug current-cluster
- show ap mesh debug forwarding-table
- show ap mesh debug hostapd-log
- show ap mesh debug meshd-log
- show ap mesh debug provisioned-clusters
- show ap mesh neighbors
- show ap mesh tech-support
- show ap mesh topology
- show ap mesh-cluster-profile
- show ap mesh-ht-ssid-profile
- show ap mesh-radio-profile
- show ap monitor
- show ap monitor association
- show ap monitor debug
- show ap monitor stats
- show ap pcap status
- show ap profile-usage
- show ap provisioning
- show ap radio-database
- show ap regulatory-domain-profile
- show ap remote counters
- show ap remote debug flash-config
- show ap remote debug mgmt-frames
- show ap spectrum-load-balancing
- show ap system-profile
- show ap tech-support
- show ap vlan-usage
- show ap wired stats
- show ap wired-ap-profile
- show ap wired-port-profile
- show ap wmm-flow
- show ap-group
- show ap-name
- show arp
- show audit-trail
- show auth-tracebuf
- show banner
- show boot
- show cellular profile
- show clock
- show command-mapping
- show configuration
- show controller-ip
- show country
- show cp-bwcontracts
- show cpuload
- show crypto dp
- show crypto dynamic-map
- show crypto ipsec
- show crypto isakmp
- show crypto map
- show crypto pki
- show crypto-local ipsec-map
- show crypto-local isakmp
- show crypto-local pki
- show database
- show datapath
- show destination
- show dialer group
- show dir
- show dot1x ap-table
- show dot1x ap-table aes
- show dot1x ap-table dynamic-wep
- show dot1x ap-table static-wep
- show dot1x ap-table tkip
- show dot1x counters
- show dot1x supplicant-info
- show dot1x supplicant-info list-all
- show dot1x supplicant-info pmkid
- show dot1x supplicant-info statistics
- show esi groups
- show esi parser
- show esi ping
- show esi servers
- show faults
- show firewall
- show firewall-cp
- show gateway health-check
- show global-user-table count
- show-global-user-table list
- show guest-access-email
- show hostname
- show ids dos-profile
- show ids general-profile
- show ids impersonation-profile
- show ids profile
- show ids rate-thresholds-profile
- show ids signature-matching-profile
- show ids signature-profile
- show ids unauthorized-device-profile
- show image version
- show interface counters
- show interface gigabitethernet
- show interface fastethernet
- show interface loopback
- show interface mgmt
- show interface port-channel
- show interface tunnel
- show interface vlan
- show inventory
- show ip access-group
- show ip access-list
- show ip cp-redirect-address
- show ip dhcp
- show ip domain-name
- show ip igmp
- show ip mobile
- show ip nat pool
- show ip ospf
- show ip pppoe-info
- show ip radius
- show ip route
- show ipc statistics app-ap
- show ipc statistics app-id
- show ipc statistics app-name
- show ipv6 access-list
- show ipv6 datapath session counters
- show ipv6 datapath session table
- show ipv6 datapath user counters
- show ipv6 datapath user table
- show ipv6 firewall
- show ipv6 mld config
- show ipv6 mld counters
- show ipv6 mld group
- show ipv6 mld interface
- show ipv6 user-table
- show keys
- show lacp
- show lacp sys-id
- show license
- show license-usage
- show localip
- show local-userdb
- show local-userdb username
- show log all
- show log ap-debug
- show log bssid-debug
- show log errorlog
- show log essid-debug
- show log network
- show log security
- show log system
- show log user
- show log user-debug
- show log wireless
- show logging
- show loginsessions
- show mac-address-table
- show master-local stats
- show master-redundancy
- show memory
- show mgmt-role
- show mgmt-users
- show mux config
- show mux state
- show netdestination
- show netservice
- show netstat
- show network-printer
- show network-storage
- show ntp peer
- show ntp servers
- show ntp status
- show packet-capture
- show packet-capture-defaults
- show papi-security
- show poe
- show port link-event
- show port monitor
- show port mux
- show port stats
- show port status
- show port trusted
- show port xsec
- show priority-map
- show processes
- show profile-errors
- show profile-hierarchy
- show profile-list aaa
- show profile-list ap
- show profile-list ap-group
- show profile-list ap-name
- show profile-list ids
- show profile-list rf
- show profile-list wlan
- show provisioning-ap-list
- show provisioning-params
- show rap-wml
- show references aaa authentication
- show references aaa authentication-server
- show references aaa profile
- show references aaa server-group
- show references ap
- show references guest-access-email
- show references ids
- show references papi-security
- show references rf
- show references user-role
- show references web-server
- show references wlan
- show rf arm-profile
- show rf dot11a-radio-profile
- show rf dot11g-radio-profile
- show rf event-thresholds-profile
- show rf ht-radio-profile
- show rf optimization-profile
- show rft profile
- show rft result
- show rft transactions
- show rights
- show roleinfo
- show rrm dot11k admission-capacity
- show rrm dot11k ap-channel-report
- show rrm dot11k beacon-report
- show rrm dot11k neighbor-report
- show rrm dot11k transmit-stream-report station-mac
- show running-config
- show session-acl-list
- show slots
- show snmp community
- show snmp inform
- show snmp trap-host
- show snmp trap-list
- show snmp trap-queue
- show snmp user-table
- show ssh
- show startup-config
- show station-table
- show storage
- show switch ip
- show switch software
- show switches
- show switchinfo
- show syscontact
- show syslocation
- show tech-support
- show telnet
- show time-range
- show tpm cert-info
- show trunk
- show uplink
- show usb
- show user
- show user_session_count
- show util_proc
- show valid-network-oui-profile
- show version
- show vlan
- show vlan mapping
- show vlan status
- show vlan summary
- tar
- show voice call-cdrs
- show voice call-counters
- show voice call-density
- show voice call-perf
- show voice call-quality
- show voice call-stats
- show voice client-status
- show voice dialplan-profile
- show voice msg-stats
- show voice prioritization
- show voice rtcp-inactivity
- show voice statistics
- show voice trace
- show vpdn l2tp configuration
- show vpdn pptp configuration
- show vpdn pptp local pool
- show via
- show vpn-dialer
- show vrrp
- show web-server
- show wlan dot11k-profile
- show wlan edca-parameters-profile
- show wlan ht-ssid-profile
- show wlan ssid-profile
- show wlan traffic-management-profile
- show wlan virtual-ap
- show wlan voip-cac-profile
- show wms ap
- show wms channel
- show wms client
- show wms counters
- show wms general
- show wms monitor-summary
- show wms probe
- show wms rogue-ap
- show wms routers
- show wms system
- show wms wired-mac
- shutdown
- snmp-server
- spanning-tree (Global Configuration)
- spanning-tree (Configuration Interface)
- ssh
- stm
- support
- syscontact
- syslocation
- telnet
- time-range
- traceroute
- trusted
- uplink
- usb reclassify
- user-role
- vlan
- valid-network-oui-profile
- vlan-name
- voice
- voip
- vpdn group l2tp
- vpdn group pptp
- vpn-dialer
- vrrp
- web-server
- whitelist-db cpsec add
- whitelist-db cpsec delete
- whitelist-db cpsec modify
- whitelist-db cpsec revoke
- whitelist-db cpsec purge
- whitelist-db cpsec-local-ctlr-list
- whitelist-db cpsec-master-ctlr-list
- whoami
- wlan dot11k-profile
- wlan client-wlan-profile
- wlan edca-parameters-profile
- wlan ht-ssid-profile
- wlan ssid-profile
- wlan traffic-management-profile
- wlan virtual-ap
- wlan voip-cac-profile
- wms ap
- wms clean-db
- wms client
- wms export-class
- wms export-db
- wms general
- wms import-db
- wms reinit-db
- wms-local system
- write
- Appendix A: Command Modes
Dell PowerConnect ArubaOS 5.0 Command Line Interface | Reference Guide ids unauthorized-device-profile | 265
Example
The following command copies the settings from the ids-unauthorized-device-disabled profile and then enables
detection and protection from adhoc networks:
ids unauthorized-device-profile unauth1
clone ids-unauthorized-device-disabled
detect-adhoc-network
protect-adhoc-network
Suspected rogue containment
confidence level
60 60 60
Protect valid stations false false true
Detect bad WEP false true true
Detect misconfigured AP false true true
Protect misconfigured AP false false true
Protect SSID false false true
Privacy false false true
Require WPA false true false
Valid 802.11g channel for policy
enforcement
—— —
Valid 802.11a channel for policy
enforcement
—— —
Valid MAC OUIs — — —
Valid and protected SSIDs — — —
Protect 802.11n High-throughput
Devices
false false true
Protect 40 MHz 802.11n High-
throughput Devices
false false true
Detect Active 802.11n Greenfield
Mode
false true true
Parameter
ids-unauthorized-
device-disabled
ids-unauthorized-device-
medium-setting
ids-unauthorized-high-
setting