Wireless Access

last person joined: yesterday 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

IDS Signature match and containment

This thread has been viewed 0 times
  • 1.  IDS Signature match and containment

    Posted Mar 07, 2013 01:57 AM

    Hi,

     

    We are using OS 6.1 and we need to auto-contain systems that emits signatures that matches our IDS signatures. I looked at the documentation for containment of signals/ signatures that matches a specific IDS signature but it does not say how and where is this configured. Please provide some guidance if you know. Thanks.

     



  • 2.  RE: IDS Signature match and containment
    Best Answer

    EMPLOYEE
    Posted Mar 07, 2013 05:51 AM

    You can only detect signatures and report them.

     



  • 3.  RE: IDS Signature match and containment

    Posted Mar 07, 2013 09:37 AM

    This is a surprise to me. Thanks.



  • 4.  RE: IDS Signature match and containment

    Posted May 28, 2014 10:49 PM

     

    So we can´t contain a deauth attack? 

     

    Regards.



  • 5.  RE: IDS Signature match and containment

    Posted May 31, 2014 08:36 AM

    look at the last reply, you can do something if you use 6.4 and the client support 802.11w:

    http://community.arubanetworks.com/t5/Unified-Wired-Wireless-Access/Block-deauth-attack-with-Aruba-WIPS/td-p/165634

     

    but in general deauth attack is a tricky attack to mitigate, you cant prevent a client from sending things into the air.



  • 6.  RE: IDS Signature match and containment

    Posted Jun 02, 2014 10:43 AM

    Ok, thanks.