显示id general-profile
显示id general-profile
Description
Displays an IDS General Profile. Issue this command without the
parameter to display the IDS General Profile list. Include a profile name to display detailed configuration information for that profile.
Parameter |
Description |
Name of an IDS General Profile. |
Examples
The following example shows that themanaged devicehas four configured General Profiles:
(host) [mynode] (config) # show ids general-profile
IDS General Profile List
------------------------
Name References Profile Status
---- ---------- --------------
default 2
helen 0
wired-lb 1
Wizard-test2 1
Total: 4
In the example above, theReferencecolumn indicates the number of references to the profile named in theNamecolumn. TheProfile Statuscolumn is blank unless the rule is predefined.
The following example displays the settings for the profiledefault:
(host)[mynode] (config) #show ids general-profile default
IDS General Profile "default"
-----------------------------
Parameter Value
--------- -----
Adhoc AP Max Unseen Timeout 180 sec
Adhoc (IBSS) AP Inactivity Timeout 5 sec
AP Inactivity Timeout 20 sec
AP Max Unseen Timeout 600 sec
AP Neighbors Message Interval 180 sec
AP Neighbors Message false
Client Detection Mode normal
Frame Types for RSSI calculation ba pr dlow dnull mgmt ctrl
IDS Event Generation on AP logs-and-traps
Max Monitored Devices 0
Max Monitored APs 0
Max Unassociated Stations 512
Min Potential AP Beacon Rate 25 %
Min Potential AP Monitor Time 2 sec
Mobility Manager RTLS false
Monitored Device Stats Update Interval 0 sec
Packet SNR Threshold 0
Send Adhoc Info to Controller false
Signature Quiet Time 900 sec
STA Inactivity Timeout 60 sec
STA Max Unseen Timeout 600 sec
Station RSSI Message Interval 60 sec
Station RSSI Message false
Radio Info Ext Message Interval 300 sec
Stats Update Interval 60 sec
Unclassified AP Update false
Unclassified STA Update false
Unclassified Device Update Interval 60 sec
Wired Containment false
Wired Containment of AP's Adj MACs false
Wired Containment of Suspected L3 Rogue false
Wireless Containment deauth-only
Wireless Containment Deauth Reason 3
Debug Wireless Containment false
WMS Client Monitoring all
The output of this command includes the following parameters:
Parameter |
Description |
Adhoc AP Max Unseen Timeout |
Ageout time in seconds since ad hoc (IBSS) AP was last seen. |
Adhoc (IBSS) AP Inactivity Timeout |
Ad hoc (IBSS) AP inactivity timeout in number of scans. |
AP Inactivity Timeout |
Time, in seconds, after which an AP is aged out. |
AP Max Unseen Timeout |
Ageout time, in seconds, since AP was last seen. |
Frame Types for RSSI calculation |
Frame types used in AM RSSI calculation. |
IDS Event Generation on AP |
Enable or disable IDS event generation from the AP. Event generation from the AP can be enabled for syslogs, traps, or both. This does not affect generation of IDS correlated events on the switch. |
Max Monitored Devices |
Maximum number of APs and stations that can be monitored. This number does not include stations that are not associated to any AP. Within this max value, the AP reserves a buffer for stations that are associated locally. |
Max Monitored APs |
最大数量的APs监测。 Default value: 0 |
Max Monitored Stations |
Maximum number of monitored stations. |
Max Unassociated Stations |
Maximum number of unassociated stations. |
Min Potential AP Beacon Rate |
Minimum beacon rate acceptable from a potential AP, in percentage of the advertised beacon interval. |
Min Potential AP Monitor Time |
Minimum time, in seconds, a potential AP has to be up before it is classified as a real AP. |
Mobility Manager RTLS |
Shows if RTLS communication with the configured mobility-manager is enabled or disabled. |
Monitored Device Stats Update Interval |
Time interval, in seconds, for AP to update the switch with stats for monitored devices. Minimum is 60. |
Packet SNR Threshold |
The packet Signal to Noise Ratio (SNR) threshold. All packets with SNR below this threshold is dropped from IDS and ARM processing. No packets are dropped if the threshold is set to 0. |
Send Adhoc Info to Controller |
Enable or disable sending adhoc information to themanaged devicefrom the AP. |
Signature Quiet Time |
After a signature match is detected, the time to wait, in seconds, to resume checking. |
STA Inactivity Timeout |
Time, in seconds, after which a station is aged out. |
STA Max Unseen Timeout |
Time, in seconds, after which an AP is aged out. |
Station RSSI Message Interval |
Interval, in seconds, at which the AP delivers station RSSI messages to the management server. The range value is 1-36000. The default value is 1 second. |
Station RSSI Message |
Enables or disables station RSSI messages. The default value is disabled. |
Stats Update Interval |
Interval, in seconds, for the AP to update themanaged devicewith statistics. This setting takes effect only if theArubaMobility Manager is configured. Otherwise, statistics update to themanaged deviceis disabled. |
Unclassified AP Update |
Enables or disables classification updates for monitored APs. If this option is enabled, there is a decrease in the delay with which the devices are classified. The default value is disabled. |
Unclassified STA Update |
Enables or disables classification updates for monitored clients. If this option is enabled, there is a decrease in the delay with which the devices are classified. The default value is disabled. |
Unclassified Device Update Interval |
The time interval, in seconds, for the AP to send the WMS a list of unclassified APs and clients. The range value is 30-36000 seconds. The default value is 60 seconds. |
Wired Containment |
显示如果教授ile has enabled or disabled containment from the wired side. |
Wired Containment of AP's Adj MACs |
显示如果教授ile has enabled or disabled wired containment of MACs offset by one from APs BSSID. |
Wired Containment of Suspected L3 Rogue |
显示如果教授ile has enabled or disabled the feature to identify and contain an AP with a preset wired MAC address that is completely different from the AP’s BSSID. where the MAC address that the AP provides to wireless clients as a ‘gateway MAC’ is offset by one character from its wired MAC address. |
Wireless Containment |
显示如果教授ile has enabled or disabled containment from the wireless side. |
Wireless Containment Deauth Reason |
Specify deauth reason for containment from the wireless side. Range: 1 - 134 Default: 3 |
Debug Wireless Containment |
显示如果教授ile has enabled or disable debugging of containment from the wireless side. |
Wired Containment of AP’s Adj MACs |
Enable or disable wired containment of MACs offset by one from APs BSSID. |
Related Commands
Command |
Description |
This command configures an IDS general profile. |
Command History
Release |
Modification |
ArubaOS8.9.0.0 |
The output of the command was modified to displayWireless Containment Deauth ReasonandMax Monitored APs. |
ArubaOS8.0.0.0 |
Command Introduced. |
Command Information
Platforms |
License |
Command Mode |
All platforms |
需要RFprotect许可证。 |
Config mode onMobility Conductor. |