Configuration Guide Configuring WIDS
Configuring Flooding Attack Detection
(Optional) Flooding attack detection is disabled by default.
Run the attack-detection flood single-mac { total | assoc | reassoc | disassoc | probe | action | auth | deauth |
null-data } thresholdnumintervaltime command to configure the threshold and interval of a specified type of packets
for single-STAflooding attack in WIDS configuration mode.
Run the attack-detection flood multi-mac { assoc | reassoc | disassoc | probe | action | auth | deauth | null-data }
threshold num interval time command to configure the threshold and interval of a specified type of packets for
multi-STA flooding attack.
attack-detection flood single-mac { total | assoc | reassoc | disassoc | probe | action | auth | deauth |
null-data } threshold num interval time
single-mac: Indicates single STA detection.
total: Indicates all packets.
assoc: Indicates Association packets.
reassoc: Indicates Reassociation packets.
disassoc: Indicates Disassociation packets.
probe: Indicates Probe packets.
action: Indicates Action packets.
auth: Indicates Authentication packets.
deauth: Indicates Deauthentication packets.
null-data: Indicates Null packets.
num: Indicates the packet threshold of flooding attack detection ranging from 1 to 5,000.
time: Indicates the interval of flooding attack detection ranging from 10 to 60 seconds.
All packet thresholds of flooding attack detection, by default, 300 for single-STA, 500 for multi-STA, and 10
seconds of the statistic interval
attack-detection flood multi-mac { assoc | reassoc | disassoc | probe | action | auth | deauth |
null-data } threshold num interval time
multi-mac: Indicates multi-STA detection.
assoc: Indicates Association packets.
reassoc: Indicates Reassociation packets.
disassoc: Indicates Disassociation packets.
probe: Indicates Probe packets.
action: Indicates Action packets.