Switch Security
6-43
5. To create a new WLAN Firewall rule configure the following information:
6. Refer to the
Status
field for the state of the requests made from applet. This field displays error
messages if something goes wrong in the transaction between the applet and the switch.
7. Click
OK
to use the changes to the running configuration and close the dialog.
8. Click
Cancel
to close the dialog without committing updates to the running configuration.
6.4.14 Configuring Denial of Service (DoS) Attack Firewall Rules
To review Denial of Service Attack firewall rules:
1. Select
Security
>
Wireless Firewall
from the main tree menu.
2. Click the
Configuration
tab.
3. Click the
DoS Attack
tab.
WLAN Index
Select a WLAN index number from the pull-down menu. This number is configured
on the wireless LAN configuration page.
Broadcast Storm
Threshold
Enter the Broadcast Storm Threshold for each interface. When the rate of
broadcast packets exceeds the high threshold configured for an interface, packets
are throttled till the rate falls below the configured rate. Thresholds are configured
in terms of packets per second. The valid threshold range is 0-1000000 packets per
second.
Multicast Storm
Threshold
Enter the Multicast Storm Threshold for each interface. When the rate of multicast
packets exceeds the high threshold configured for an interface, packets are
throttled till the rate falls below the configured rate. Thresholds are configured in
terms of packets per second. The valid threshold range is 0-1000000 packets per
second.
Unknown Unicast
Storm
Enter the Unknown Unicast Storm Threshold for each interface. When the rate of
unknown unicast packets exceeds the high threshold configured for an interface,
packets are throttled till the rate falls below the configured rate. Thresholds are
configured in terms of packets per second. The threshold range is 0-1000000
packets per second.
Allowed MU denies
per sec
Configure the permissible number of denied packets per second that a mobile unit
on this WLAN may send before it is deauthenticated. The threshold range is 0-
1000000 packets per second.
MU Deauthenticate
Configure whether or not mobile unit de-authentication is enabled for each
WLAN. If
MU Deauthenticate
is enabled any associated mobile unit which hit
the thresholds configured for storm traffic will be deauthenticated. To enable de-
authentication, check the box.
DHCP Trust
Select to enable DHCP trust on this WLAN. When disabled, any DHCP packets
received on the interface is dropped.
ARP Trust
Select to enable ARP trust on this WLAN. ARP packets received on this interface
are considered trusted and information from these packets is used to identify
rogue devices.
ARP Rate
Enter the Address Resolution Protocol (ARP) threshold.The ARP threshold
determines the number of ARP packets permissible per second. Rates can be
between 0 and 1000000
Summary of Contents for RFS Series
Page 1: ...M Motorola RFS Series Wireless LAN Switches WiNG System Reference Guide ...
Page 10: ...TOC 8 Motorola RF Switch System Reference Guide ...
Page 56: ...2 8 Motorola RF Switch System Reference ...
Page 334: ...5 52 Motorola RF Switch System Reference 2 Select the MU Status tab ...
Page 510: ...7 32 Motorola RF Switch System Reference Guide ...
Page 534: ...8 24 Motorola RF Switch System Reference Guide ...
Page 570: ...C 14 Motorola RF Switch System Reference Guide ...
Page 589: ......