Foundry Networks IronPoint 200 User Manual page 141

Hide thumbs Also See for IronPoint 200:
Table of Contents

Advertisement

A wireless clients attempts to log in but his login fails. He tries to log in five times, but all his logins are
unsuccessful. His MAC address is blocked from any further attempts for 300 seconds.
If the client tries to log in again after 300 seconds, the next login cycle starts. He has five additional login
attempts during the second 60-second login cycle. If all these logins fail, his MAC address is blocked when his
login attempts exceed five times, this time for another 300 seconds.
If after 300 seconds the client tries to log in again, the third cycle starts. He has another five attempts to log in
during the third 60-second login cycle. If all of these attempts fail, his MAC address is permanently locked out
when his login attempts exceed five times.
ids enable
This command enables the Intrusion Detection and Lockout feature.
Syntax
ids enable
no ids enable
Default Setting
Disabled
Command Mode
Global Configuration
Command Usage
• Use this command to enable the Intrusion Detection and Lockout feature. You can define intrusion
detection parameters before you enable the feature on an access point.
• This feature works with static WEP, pre-shared key, and 802.1.X authentication. Make sure one or more
of the appropriate authentication method is configured on the access point.
ids 802.1x
This command sets the maximum number of login attempts for each login cycle if 802.1X authentication is used.
Syntax
ids 802.1x <cycle-number> <number-attempts>
no ids 802.1x
• cycle-number – The login number of the cycle you are configuring. Enter 1, 2, 3. There is no default cycle
number.
• number-attempts – Enter a number for the maximum number of login attempts in the cycle being defined.
Enter a number from 1 – 65535. However, if this value is set below 4, some client supplicants may say
that this feature is not working, even though it is. To avoid this behavior, set the number of attempts per
cycle to 4 or more.
Default Setting
5 attempts per cycle
Command Mode
Global Configuration
Command Usage
This command sets the maximum number of attempts for a login cycle on this access point, if 802.1X
authentication is used. If you do not define a value for a cycle, then the default is used. Also, entering a no
ids 802.1x resets the number of attempts to the default value.
Note:
When a client is permanently blocked, then unblocked via the CLI, the CLI still sees the
December 2006
© 2006 Foundry Networks, Inc.
Intrusion Detection and Lockout
16-3

Hide quick links:

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the IronPoint 200 and is the answer not in the manual?

Table of Contents