Configuring WIDS profiles on the WLC with LANconfig

To configure a profile for the Wireless Intrusion Detection System (WIDS) with LANconfig, go to the view WLAN controller > Profiles and click on Advanced profiles.





Create or edit the WIDS profiles under Wireless IDS profiles.





Profile name
Enter an identifier for this profile. You allocate this profile name to a WLAN profile under WLAN controller > Profiles > WLAN profiles.
Note: You need to specify a profile name for the configuration of the WIDS signatures.
Wireless-IDS active
Activates or deactivates the Wireless Intrusion Detection System.
Promiscuous mode
With the ("promiscuous mode") enabled, the AP additionally receives packets that were not directed at it, but to other network participants. This mode is necessary to be able to detect the attacks listed below. However, the promiscuous mode affects the performance. For this reason, activating the promiscuous mode automatically causes frame aggregation to be switched off.
Messaging via SYSLOG
Activates or deactivates the messaging via SYSLOG. The generated SYSLOG message has the severity level "INFO" and contains the timestamp, the interface, and the trigger (type of attack and passed threshold).
Messaging via SNMP traps
Activates or deactivates the WIDS messaging via SNMP traps.
Messaging via e-mail
Activates or deactivates the messaging via e-mail.
Important: An SMTP account has to be configured in order to use messaging via e-mail.
E-mail recipient
The e-mail address of the recipient when messaging via e-mail is activated. The field must contain a valid e-mail address.
E-mail aggregate interval
This setting sets the delay in seconds before a new e-mail is sent if the WIDS is triggered again. This prevents flooding by e-mail in case of extensive attacks.

The "Signatures" tabs are used to configure the various thresholds and measuring intervals (packets per second) of the different WIDS alarm functions. These settings are used by the WIDS to determine if an attack is taking place.









The following attack scenarios can be detected by configuring the thresholds and measuring intervals:
There are typical default values set for the different attack scenarios.
Note: (*) These attacks are only detected if promiscuous mode is active.

Save the WIDS profile and then assign it to a WLAN profile under WLAN controller > Profiles > WLAN profiles.





www.lancom-systems.com

LANCOM Systems GmbH | A Rohde & Schwarz Company | Adenauerstr. 20/B2 | 52146 Wuerselen | Germany | E‑Mail info@lancom.de

LANCOM Logo