Wireless IPS or IDS Profile
The Intrusion Detection System (IDS) and Intrusion Prevention System (IPS) monitors, detects, and prevents threats in the inbound and outbound traffic. IDS monitors the network for any malicious activity and generates threat events. IPS has all the capabilities of IDS along with the ability to prevent intrusions by dropping malicious data packets. As an administrator, you can enable either IDS or IPS.
Creating an IPS or IDS Profile
To create a Wireless IPS or IDS profile, complete the following steps:
-
In the HPE Aruba Networking Central landing page, click the configuration
icon.
The Profiles tab is displayed. -
In the left navigation menu, select one of the following options:
-
Library—This is the default selection. If you create profiles in the Library, then you must assign scope and device functions to the profiles. For more information, see Assigning Scope to an IPS or IDS Profile.
-
Global—If you create profiles at the Global level, then the profiles have Global scope assigned by default.
-
Site Collections—If you create profiles at the Site Collections level, then the profiles have site collection scope assigned by default.
-
Sites—If you create profiles at the Site level, then the profiles have site scope assigned by default.
-
Devices—If you create profiles at the Device level, then the profiles have device scope assigned by default.
-
Device Groups—If you create profiles at the Device Group level, then the profiles have device group scope assigned by default.
Note:- To create profiles at the Global level, select the device type from the Device Function drop-down list before step 4.
- To create profiles at the Site Collections, Sites, Devices, and Device Group level, complete the following steps before step 4:
- Select Site Collection, Site, Device, or Device Group in the left navigation menu.
- Select a Site Collection, Site, Device, or Device Group from the list view depending on the level where you are creating the profile.
- Select the device type from the Device Function drop-down list.
-
-
On the Wireless card, click the second radio button, and then click Wireless IDS/IPS.
Alternatively, you can complete the following steps:-
On the Wireless card, click Manage.
-
On the Wireless IDS/IPS card, click Manage.
The Wireless IDS/IPS list is displayed.
-
-
Click Create Profile.
The Create Profile side panel is displayed.
-
Specify the following IPS or IDS profile parameters:
-
Create as a local profile—Select this option if you want to configure this profile as local.
Note:The Create as a local profile option is available at the Global, Site Collections, Sites, Devices, and Device Groups levels; it is not available at the Library level.
-
Name—Enter the name of the IPS or IDS profile.
-
Description—Enter the description for the IPS or IDS profile.
-
Options—Select the one or both options as required for the profile. The available options are:
-
Detection
-
Protection
-
-
Detection
-
Infrastructure Security Level—Select the required level of infrastructure security from the drop-down list. The following options are available:
-
High—Includes all the threat categories for detection. For example, if there are 28 threat categories, all 28 are selected.
-
Medium—Includes only 7 threat categories by default for detection. Click View Selected Threats to see the selected items.
-
Low—Includes only 5 threat categories by default for detection.
-
Off—Indicates that infrastructure security level is not set.
-
Custom—Allows you to select the threat categories that you want for detection.
-
-
Threats—Auto-selected based on the option selected for infrastructure security level.
-
Client Security Level—Select the required level of client security from the drop-down list. The following options are available:
-
High—Includes all the threat categories for detection. For example, if there are 16 threat categories, all 16 are selected.
-
Medium—Includes only 8 threats by default for detection. Click View Selected Threats to see the selected items.
-
Low—Includes only 1 threat by default for detection.
-
Off—Indicates that client security level is not set.
-
Custom—Allows you to choose the threat categories that you want for detection.
-
-
Threats—Auto-selected based on the option selected for client security level.
-
-
Protection
-
Infrastructure Security Level—Select the required level of infrastructure security from the drop-down list. The following options are available:
-
High—Includes all the threat categories for protection. For example, if there are 5 threat categories, all 5 are selected.
-
Low—Includes only 2 threat categories by default for protection. Click View Selected Threats to see the selected items.
-
Off—Indicates that infrastructure security level is not set.
-
Custom—Allows you to choose the threat categories that you want for protection.
-
-
Threats—Auto-selected based on the option selected for infrastructure security level.
-
Client Security Level—Select the required level of client security from the drop-down list. The following options are available:
-
High—Includes all the threat categories for protection. For example, if there are 2 threat categories, both are selected.
-
Low—Includes only 1 threat category by default for protection.
-
Off—Indicates that client security level is not set.
-
Custom—Allows you to choose the threat categories that you want for protection.
-
-
Threats—Auto-selected based on the option selected for client security level.
-
-
Containment Methods
-
Wired—Select this to contain the intrusion in wired network.
-
Wireless Containment—Select the required wireless option from the drop-down list. The available options are:
-
Deauth only
-
Tarpit all sta
-
Tarpit non valid sta
-
-
-
Protection Against Wired Attacks—Select the required protection. The available options are:
-
Drop Malicious ARP
-
Drop Malformed DHCP Packets
-
ARP Poison Check
-
Based on the selected option, the following parameters are displayed.
-
-
Click Create.
The IPS or IDS profile is created and added to the list.
-
To edit a profile, complete the following steps:
-
Click anywhere on the row of the profile in the list view.
The profile edit view is displayed in the side panel. -
Edit the required parameters.
-
Click Update.
-
-
To delete an IDS or IPS profile, hover on the profile name, and click the delete
icon. -
To search for a profile, type the profile name in the search bar.
The search bar displays dynamic results as soon as you start typing.
The following image displays the Create Profile side panel of an Wireless IDS/IPS profile.
Figure 1: Create Profile side-panel—IPS or IDS Profile
Assigning Scope to an IPS or IDS Profile
For profiles created under Library, you must assign a scope and device function to be able to use its features and functionality.
To assign scope to a profile, complete the following steps:
-
In the HPE Aruba Networking Central landing page, click the configuration
icon.
The Profiles tab is displayed. -
On the Wireless card, click Wireless IDS/IPS. Alternatively, you can complete the following steps:
-
On the Wireless card, click Manage.
-
On the Wireless IDS/IPS card, click Manage.
The Wireless IDS/IPS list view is displayed.
-
-
Hover on the profile to which you want to assign a scope and click the ellipsis
icon. -
Select Assign.
The Assign Profile side panel is displayed.
-
Select the device types from Device Function list.
-
To add a scope, click the Add
icon on the Scopes table. -
Select a scope from the following Scope Level options in the drop-down list.
-
Global—Selecting this option assigns the scope at the Global level.
-
Site Collections—Select the site collections from the Assign to Scope drop-down list.
-
Sites—Select the sites from the Assign to Scope drop-down list.
-
Devices—Select the devices from the Assign to Scope drop-down list.
-
Device Groups—Select the device groups from the Assign to Scope drop-down list .
-
-
Click Add.
The Scopes table displays the newly added scopes.
-
Click Assign.
The Wireless IDS/IPS list displays the device functions and number of scopes assigned to the profile.
-
To unassign a scope from a profile, complete the following steps:
-
Hover on the profile name and click the ellipsis
icon. -
Select Unassign.
The Unassign pop-up window is displayed.
-
Select the required scope and click Unassign.
-
-
To customize the Wireless IDS or IPS profile list, click the Customize Columns icon
. For more information, see Customizing List.