User manual

14-17
Example
RFS7000(config-wireless)#ids anomaly-detection tkip-countermeasures enable
RFS7000(config-wireless)#
RFS7000(config-wireless)#ids detect-window 250
RFS7000(config-wireless)#
RFS7000(config-wireless)#ids ex-ops 80211-replay-fails filter-ageout 5200
RFS7000(config-wireless)#
ex-ops Configures parameters related to the detection of excessive operations on
the RF network.
80211-replay-fails – 802.11 replay check failure.
all – Changes for all types of excessive operations.
association-requests – 802.11 Authentication and Association
Requests.
authentication-fails – Failure to Authenticate with Servers
(Radius/Kerberos).
crypto-replay-fails – TKIP/CCMP IV replay check failure.
decryption-fails – Decryption failures.
disassociations – Disassociation and de-authentication frames.
eap-starts – EAP (802.1x) start frames.
probe-requests – Probe request frames.
unassoc-frames – Frames from unassociated station.
filter-ageout<0-86400> – Configures number of seconds mobile units
must be filtered out.
threshold (mu|radio|switch) <0-9999> – Configures the threshold of
events allowed in the detection window.
mu–Uses the threshold value for monitoring on a per-mobile unit
basis.
radio–Uses the threshold value for monitoring on a per-radio
basis.
switch–Uses the threshold value for monitoring at the switch
level.