Network Management

last person joined: yesterday 

Keep an informative eye on your network with HPE Aruba Networking network management solutions
Expand all | Collapse all

Need suggestion about Airwave trigger for WIPS events

This thread has been viewed 2 times
  • 1.  Need suggestion about Airwave trigger for WIPS events

    Posted Jan 23, 2014 07:08 AM

    Hi all,

    I need suggestion about Airwave trigger for WIPS events.

    What WIPS event are most minatorial?

    What WIPS event should be trigger if it had been detected during a peiod of time.

    For example: set trigger if deauth attack had been detect 10 times in one day.

    Thanks

     



  • 2.  RE: Need suggestion about Airwave trigger for WIPS events

    Posted Jan 29, 2014 03:00 AM

    I get this question a lot when doing Airwave.

     

    For the unfamiliar customer (with Airwave), I always ask myself what I'd want retrospectively (having seen things after the event, that it would have been nice to alert on).

     

    I'd definately recommend alerting on full rogue classification (i.e. 100% confidence).

     

    Moving on from that, to a large extent, it depends on how much time you can dedicate yourself (or via a team-member) to pro-actively supporting the WiFi.

     

    Alerting on e.g. de-auth's and suspects is fine, but if you don't have time to go and investigate these alerts, there's not a lot of point in alerting. Assuming you do have time...

     

    Clients associating to suspect rogues is interesting, as is detecting ad-hocs and wifi-bridges (if that's frowned upon in your business). Oh, and EAP related alerts can be handy actually for client troubleshooting.

     



  • 3.  RE: Need suggestion about Airwave trigger for WIPS events
    Best Answer

    Posted Jan 29, 2014 11:08 AM

    Some of the RAPIDS rules I use are as follows

     

    1. Duplicate SSID detected on the WLAN

    Capture.PNG

    2. Detected wirelessly and on LAN

    Capture1.PNG

     

    3. Ad-hoc contained

    Capture2.PNG

     

     

    For Triggers, I setup the following:

     

    Rogue Contained

    rogue1.PNG

     

    SNMP Trap IDS event ad-hoc

    roguie2.PNG