Specifications

Intrusion Detection Configuration 309
Chapter 15
FIGURE 15-2 Rate Analysis Configuration
Configuration is divided into two sections: Channel thresholds and node
thresholds. A channel threshold applies to an entire channel, while a node
threshold applies to a particular client MAC address. All frame types are
standard management frames as defined by the 802.11 standard.
Configuration parameters are:
Channel/Node Threshold – Specifies the number of a specific type of frame
that must be exceeded within a specific interval to trigger an alarm.
Channel/Node Time – Specifies the time interval in which the threshold must
be exceeded in order to trigger an alarm.
Channel/Node Quiet Time – After an alarm has been triggered, specifies the
amount of time that must elapse before another identical alarm may be
triggered. This option prevents excessive messages in the logfile.
The equivalent CLI configuration for the above example is:
wms
ids-policy rate-frame-type-param assoc channel-threshold 30
ids-policy rate-frame-type-param assoc channel-inc-time 3