Reference Guide

Table Of Contents
215 | ids dos-profile Dell PowerConnect ArubaOS 6.0 Command Line Interface | Reference Guide
Syntax
Parameter Description Range Default
<profile> Name that identifies an instance of the profile. The
name must be 1-63 characters.
“default”
ap-flood-inc-time Time, in seconds, during which a configured
number of fake AP beacons must be received to
trigger an alarm.
0-36000 3600
seconds
ap-flood-quiet-time After an alarm has been triggered by a fake AP
flood, the time, in seconds, that must elapse before
an identical alarm may be triggered.
60-360000 900
seconds
ap-flood-threshold Number of fake AP beacons that must be received
within the flood increase time to trigger an alarm.
0-100,000 50
assoc-rate-thresholds Rate threshold for associate request frames.
auth-rate-thresholds Rate threshold for authenticate frames.
block-ack-dos-quiet-time Time to wait, in seconds, after detecting an
attempt to reset the receive window using a
forged block ACK add.
60-360000
seconds
900
seconds
chopchop-quiet-time Time to wait, in seconds, after detecting a
ChopChop attack after which the check can be
resumed.
60-360000
seconds
900
seconds
client-ht-40mhz-intol-quiet-
time <seconds>
Controls the quiet time (when to stop reporting
intolerant STAs if they have not been detected), in
seconds, for detection of 802.11n 40 MHz
intolerance setting.
60-360000
seconds
900
seconds
client-flood-inc-time Number of consecutive seconds over which the
client count is more than the threshold.
0-36000
seconds
3 seconds
client-flood-quiet-time Time to wait, in seconds, after detecting a client
flood before continuing the check.
60-360000
seconds
900
seconds
client-flood-threshold Threshold for the number of spurious clients in the
system.
0-100000 150
clone Copy data from another IDS Denial Of Service
Profile.
——
cts-rate-quiet-time Time to wait, in seconds, after detecting a CTS rate
anomaly after which the check can be resumed.
60-360000
seconds
900
seconds
cts-rate-threshold Number of CTS control packets over the time
interval that constitutes an anomaly.
0-100000 5000
cts-rate-time-interval Time interval, in seconds, over which the packet
count should be checked.
1-120
seconds
5 seconds
deauth-rate-thresholds Rate threshold for deauthenticate frames.
detect-ap-flood Enables detection of flooding with fake AP
beacons to confuse legitimate users and to
increase the amount of processing needed on
client operating systems.
true
false
false
detect-bl
ock-ack-dos Enable/disable detection of attempts to reset
traffic receive windows using forged Block ACK
Add messages.
true
false
true
detect-chopchop-attack Enable/disable detection of ChopChop attack. true
false
false