Nortel Networks NN47250-500 Switch User Manual


 
Rogue detection and counter measures 717
Nortel WLAN—Security Switch 2300 Series Configuration Guide
Disabling or reenabling logging of rogues
By default, a WSS generates a log message when a rogue is detected or disappears. To disable or reenable the log
messages, use the following command:
set rfdetect log {enable | disable}
To display log messages on a switch, use the following command:
show log buffer
(This command has optional parameters. For complete syntax information, see the Nortel WLAN Security Switch 2300
Series Command Line Reference.)
Enabling rogue and countermeasures notifications
By default, all SNMP notifications (informs or traps) are disabled. To enable or disable notifications for rogue detection,
Intrusion Detection System (IDS), and Denial of Service (DoS) protection, configure a notification profile that sends all
the notification types for these features. (For syntax information and an example, see “Configuring a notification profile”
on page 202.)
IDS and DoS alerts
WSS Software can detect illegitimate network access attempts and attempts to disrupt network service. In response,
WSS Software generates messages and SNMP notifications. The following sections describe the types of attacks and
security risks that WSS Software can detect.
For examples of the log messages that WSS Software generates when DoS attacks or other security risks are detected,
see “IDS log message examples” on page 726.
For information about the notifications, see “Configuring a notification profile” on page 202.
Note. To detect DoS attacks, Scheduled RF Scanning must be enabled. (See “Disabling
or reenabling Scheduled RF Scanning” on page 716.)