config wireless-controller wids-profile
Configure wireless intrusion detection system (WIDS) profiles.
config wireless-controller wids-profile
Description: Configure wireless intrusion detection system (WIDS) profiles.
edit <name>
set adhoc-network [enable|disable]
set adhoc-valid-ssid [enable|disable]
set air-jack [enable|disable]
set ap-auto-suppress [enable|disable]
set ap-bgscan-disable-schedules <name1>, <name2>, ...
set ap-bgscan-duration {integer}
set ap-bgscan-idle {integer}
set ap-bgscan-intv {integer}
set ap-bgscan-period {integer}
set ap-bgscan-report-intv {integer}
set ap-fgscan-report-intv {integer}
set ap-impersonation [enable|disable]
set ap-scan [disable|enable]
set ap-scan-channel-list-2G-5G <chan1>, <chan2>, ...
set ap-scan-channel-list-6G <chan1>, <chan2>, ...
set ap-scan-passive [enable|disable]
set ap-scan-threshold {string}
set ap-spoofing [enable|disable]
set asleap-attack [enable|disable]
set assoc-flood-thresh {integer}
set assoc-flood-time {integer}
set assoc-frame-flood [enable|disable]
set auth-flood-thresh {integer}
set auth-flood-time {integer}
set auth-frame-flood [enable|disable]
set bcn-flood [enable|disable]
set bcn-flood-thresh {integer}
set bcn-flood-time {integer}
set beacon-wrong-channel [enable|disable]
set block_ack-flood [enable|disable]
set block_ack-flood-thresh {integer}
set block_ack-flood-time {integer}
set chan-based-mitm [enable|disable]
set client-flood [enable|disable]
set client-flood-thresh {integer}
set client-flood-time {integer}
set comment {string}
set cts-flood [enable|disable]
set cts-flood-thresh {integer}
set cts-flood-time {integer}
set deauth-broadcast [enable|disable]
set deauth-unknown-src-thresh {integer}
set disassoc-broadcast [enable|disable]
set disconnect-station [enable|disable]
set eapol-fail-flood [enable|disable]
set eapol-fail-intv {integer}
set eapol-fail-thresh {integer}
set eapol-key-overflow [enable|disable]
set eapol-logoff-flood [enable|disable]
set eapol-logoff-intv {integer}
set eapol-logoff-thresh {integer}
set eapol-pre-fail-flood [enable|disable]
set eapol-pre-fail-intv {integer}
set eapol-pre-fail-thresh {integer}
set eapol-pre-succ-flood [enable|disable]
set eapol-pre-succ-intv {integer}
set eapol-pre-succ-thresh {integer}
set eapol-start-flood [enable|disable]
set eapol-start-intv {integer}
set eapol-start-thresh {integer}
set eapol-succ-flood [enable|disable]
set eapol-succ-intv {integer}
set eapol-succ-thresh {integer}
set fata-jack [enable|disable]
set fuzzed-beacon [enable|disable]
set fuzzed-probe-request [enable|disable]
set fuzzed-probe-response [enable|disable]
set hotspotter-attack [enable|disable]
set ht-40mhz-intolerance [enable|disable]
set ht-greenfield [enable|disable]
set invalid-addr-combination [enable|disable]
set invalid-mac-oui [enable|disable]
set long-duration-attack [enable|disable]
set long-duration-thresh {integer}
set malformed-association [enable|disable]
set malformed-auth [enable|disable]
set malformed-ht-ie [enable|disable]
set netstumbler [enable|disable]
set netstumbler-thresh {integer}
set netstumbler-time {integer}
set null-ssid-probe-resp [enable|disable]
set omerta-attack [enable|disable]
set overflow-ie [enable|disable]
set probe-flood [enable|disable]
set probe-flood-thresh {integer}
set probe-flood-time {integer}
set pspoll-flood [enable|disable]
set pspoll-flood-thresh {integer}
set pspoll-flood-time {integer}
set pwsave-dos-attack [enable|disable]
set reassoc-flood [enable|disable]
set reassoc-flood-thresh {integer}
set reassoc-flood-time {integer}
set risky-encryption [enable|disable]
set rts-flood [enable|disable]
set rts-flood-thresh {integer}
set rts-flood-time {integer}
set sensor-mode [disable|foreign|...]
set spoofed-deauth [enable|disable]
set unencrypted-valid [enable|disable]
set valid-client-misassociation [enable|disable]
set valid-ssid-misuse [enable|disable]
set weak-wep-iv [enable|disable]
set wellenreiter [enable|disable]
set wellenreiter-thresh {integer}
set wellenreiter-time {integer}
set windows-bridge [enable|disable]
set wireless-bridge [enable|disable]
set wpa-ft-attack [enable|disable]
next
end
config wireless-controller wids-profile
|
Parameter |
Description |
Type |
Size |
Default |
||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
adhoc-network |
Enable/disable adhoc network detection (default = disable). |
option |
- |
disable |
||||||||
|
|
|
|||||||||||
|
adhoc-valid-ssid |
Enable/disable adhoc using valid SSID detection (default = disable). |
option |
- |
disable |
||||||||
|
|
|
|||||||||||
|
air-jack |
Enable/disable AirJack detection (default = disable). |
option |
- |
disable |
||||||||
|
|
|
|||||||||||
|
ap-auto-suppress |
Enable/disable on-wire rogue AP auto-suppression (default = disable). |
option |
- |
disable |
||||||||
|
|
|
|||||||||||
|
ap-bgscan-disable-schedules |
Firewall schedules for turning off FortiAP radio background scan. Background scan will be disabled when at least one of the schedules is valid. Separate multiple schedule names with a space. Schedule name. |
string |
Maximum length: 35 |
|
||||||||
|
ap-bgscan-duration |
Listen time on scanning a channel (10 - 1000 msec, default = 30). |
integer |
Minimum value: 10 Maximum value: 1000 |
30 |
||||||||
|
ap-bgscan-idle |
Wait time for channel inactivity before scanning this channel (0 - 1000 msec, default = 20). |
integer |
Minimum value: 0 Maximum value: 1000 |
20 |
||||||||
|
ap-bgscan-intv |
Period between successive channel scans (1 - 600 sec, default = 3). |
integer |
Minimum value: 1 Maximum value: 600 |
3 |
||||||||
|
ap-bgscan-period |
Period between background scans (10 - 3600 sec, default = 600). |
integer |
Minimum value: 10 Maximum value: 3600 |
600 |
||||||||
|
ap-bgscan-report-intv |
Period between background scan reports (15 - 600 sec, default = 30). |
integer |
Minimum value: 15 Maximum value: 600 |
30 |
||||||||
|
ap-fgscan-report-intv |
Period between foreground scan reports (15 - 600 sec, default = 15). |
integer |
Minimum value: 15 Maximum value: 600 |
15 |
||||||||
|
ap-impersonation |
Enable/disable AP impersonation detection (default = disable). |
option |
- |
disable |
||||||||
|
|
|
|||||||||||
|
ap-scan |
Enable/disable rogue AP detection. |
option |
- |
disable |
||||||||
|
|
|
|||||||||||
|
ap-scan-channel-list-2G-5G |
Selected ap scan channel list for 2.4G and 5G bands. Channel number. |
string |
Maximum length: 3 |
|
||||||||
|
ap-scan-channel-list-6G |
Selected ap scan channel list for 6G band. Channel 6g number. |
string |
Maximum length: 3 |
|
||||||||
|
ap-scan-passive |
Enable/disable passive scanning. Enable means do not send probe request on any channels (default = disable). |
option |
- |
disable |
||||||||
|
|
|
|||||||||||
|
ap-scan-threshold |
Minimum signal level/threshold in dBm required for the AP to report detected rogue AP (-95 to -20, default = -90). |
string |
Maximum length: 7 |
-90 |
||||||||
|
ap-spoofing |
Enable/disable AP spoofing detection (default = disable). |
option |
- |
disable |
||||||||
|
|
|
|||||||||||
|
asleap-attack |
Enable/disable asleap attack detection (default = disable). |
option |
- |
disable |
||||||||
|
|
|
|||||||||||
|
assoc-flood-thresh |
The threshold value for association frame flooding. |
integer |
Minimum value: 1 Maximum value: 100 |
30 |
||||||||
|
assoc-flood-time |
Number of seconds after which a station is considered not connected. |
integer |
Minimum value: 5 Maximum value: 120 |
10 |
||||||||
|
assoc-frame-flood |
Enable/disable association frame flooding detection (default = disable). |
option |
- |
disable |
||||||||
|
|
|
|||||||||||
|
auth-flood-thresh |
The threshold value for authentication frame flooding. |
integer |
Minimum value: 1 Maximum value: 100 |
30 |
||||||||
|
auth-flood-time |
Number of seconds after which a station is considered not connected. |
integer |
Minimum value: 5 Maximum value: 120 |
10 |
||||||||
|
auth-frame-flood |
Enable/disable authentication frame flooding detection (default = disable). |
option |
- |
disable |
||||||||
|
|
|
|||||||||||
|
bcn-flood |
Enable/disable bcn flood detection (default = disable). |
option |
- |
disable |
||||||||
|
|
|
|||||||||||
|
bcn-flood-thresh |
The threshold value for bcn flood. |
integer |
Minimum value: 1 Maximum value: 65100 |
15 |
||||||||
|
bcn-flood-time |
Detection Window Period. |
integer |
Minimum value: 1 Maximum value: 120 |
1 |
||||||||
|
beacon-wrong-channel |
Enable/disable beacon wrong channel detection (default = disable). |
option |
- |
disable |
||||||||
|
|
|
|||||||||||
|
block_ack-flood |
Enable/disable block_ack flood detection (default = disable). |
option |
- |
disable |
||||||||
|
|
|
|||||||||||
|
block_ack-flood-thresh |
The threshold value for block_ack flood. |
integer |
Minimum value: 1 Maximum value: 65100 |
50 |
||||||||
|
block_ack-flood-time |
Detection Window Period. |
integer |
Minimum value: 1 Maximum value: 120 |
1 |
||||||||
|
chan-based-mitm |
Enable/disable channel based mitm detection (default = disable). |
option |
- |
disable |
||||||||
|
|
|
|||||||||||
|
client-flood |
Enable/disable client flood detection (default = disable). |
option |
- |
disable |
||||||||
|
|
|
|||||||||||
|
client-flood-thresh |
The threshold value for client flood. |
integer |
Minimum value: 1 Maximum value: 65100 |
30 |
||||||||
|
client-flood-time |
Detection Window Period. |
integer |
Minimum value: 1 Maximum value: 120 |
10 |
||||||||
|
comment |
Comment. |
string |
Maximum length: 63 |
|
||||||||
|
cts-flood |
Enable/disable cts flood detection (default = disable). |
option |
- |
disable |
||||||||
|
|
|
|||||||||||
|
cts-flood-thresh |
The threshold value for cts flood. |
integer |
Minimum value: 1 Maximum value: 65100 |
30 |
||||||||
|
cts-flood-time |
Detection Window Period. |
integer |
Minimum value: 1 Maximum value: 120 |
10 |
||||||||
|
deauth-broadcast |
Enable/disable broadcasting de-authentication detection (default = disable). |
option |
- |
disable |
||||||||
|
|
|
|||||||||||
|
deauth-unknown-src-thresh |
Threshold value per second to deauth unknown src for DoS attack (0: no limit). |
integer |
Minimum value: 0 Maximum value: 65535 |
10 |
||||||||
|
disassoc-broadcast |
Enable/disable broadcast dis-association detection (default = disable). |
option |
- |
disable |
||||||||
|
|
|
|||||||||||
|
disconnect-station |
Enable/disable disconnect station detection (default = disable). |
option |
- |
disable |
||||||||
|
|
|
|||||||||||
|
eapol-fail-flood |
Enable/disable EAPOL-Failure flooding (to AP) detection (default = disable). |
option |
- |
disable |
||||||||
|
|
|
|||||||||||
|
eapol-fail-intv |
The detection interval for EAPOL-Failure flooding (1 - 3600 sec). |
integer |
Minimum value: 1 Maximum value: 3600 |
1 |
||||||||
|
eapol-fail-thresh |
The threshold value for EAPOL-Failure flooding in specified interval. |
integer |
Minimum value: 2 Maximum value: 100 |
10 |
||||||||
|
eapol-key-overflow |
Enable/disable overflow EAPOL key detection (default = disable). |
option |
- |
disable |
||||||||
|
|
|
|||||||||||
|
eapol-logoff-flood |
Enable/disable EAPOL-Logoff flooding (to AP) detection (default = disable). |
option |
- |
disable |
||||||||
|
|
|
|||||||||||
|
eapol-logoff-intv |
The detection interval for EAPOL-Logoff flooding (1 - 3600 sec). |
integer |
Minimum value: 1 Maximum value: 3600 |
1 |
||||||||
|
eapol-logoff-thresh |
The threshold value for EAPOL-Logoff flooding in specified interval. |
integer |
Minimum value: 2 Maximum value: 100 |
10 |
||||||||
|
eapol-pre-fail-flood |
Enable/disable premature EAPOL-Failure flooding (to STA) detection (default = disable). |
option |
- |
disable |
||||||||
|
|
|
|||||||||||
|
eapol-pre-fail-intv |
The detection interval for premature EAPOL-Failure flooding (1 - 3600 sec). |
integer |
Minimum value: 1 Maximum value: 3600 |
1 |
||||||||
|
eapol-pre-fail-thresh |
The threshold value for premature EAPOL-Failure flooding in specified interval. |
integer |
Minimum value: 2 Maximum value: 100 |
10 |
||||||||
|
eapol-pre-succ-flood |
Enable/disable premature EAPOL-Success flooding (to STA) detection (default = disable). |
option |
- |
disable |
||||||||
|
|
|
|||||||||||
|
eapol-pre-succ-intv |
The detection interval for premature EAPOL-Success flooding (1 - 3600 sec). |
integer |
Minimum value: 1 Maximum value: 3600 |
1 |
||||||||
|
eapol-pre-succ-thresh |
The threshold value for premature EAPOL-Success flooding in specified interval. |
integer |
Minimum value: 2 Maximum value: 100 |
10 |
||||||||
|
eapol-start-flood |
Enable/disable EAPOL-Start flooding (to AP) detection (default = disable). |
option |
- |
disable |
||||||||
|
|
|
|||||||||||
|
eapol-start-intv |
The detection interval for EAPOL-Start flooding (1 - 3600 sec). |
integer |
Minimum value: 1 Maximum value: 3600 |
1 |
||||||||
|
eapol-start-thresh |
The threshold value for EAPOL-Start flooding in specified interval. |
integer |
Minimum value: 2 Maximum value: 100 |
10 |
||||||||
|
eapol-succ-flood |
Enable/disable EAPOL-Success flooding (to AP) detection (default = disable). |
option |
- |
disable |
||||||||
|
|
|
|||||||||||
|
eapol-succ-intv |
The detection interval for EAPOL-Success flooding (1 - 3600 sec). |
integer |
Minimum value: 1 Maximum value: 3600 |
1 |
||||||||
|
eapol-succ-thresh |
The threshold value for EAPOL-Success flooding in specified interval. |
integer |
Minimum value: 2 Maximum value: 100 |
10 |
||||||||
|
fata-jack |
Enable/disable FATA-Jack detection (default = disable). |
option |
- |
disable |
||||||||
|
|
|
|||||||||||
|
fuzzed-beacon |
Enable/disable fuzzed beacon detection (default = disable). |
option |
- |
disable |
||||||||
|
|
|
|||||||||||
|
fuzzed-probe-request |
Enable/disable fuzzed probe request detection (default = disable). |
option |
- |
disable |
||||||||
|
|
|
|||||||||||
|
fuzzed-probe-response |
Enable/disable fuzzed probe response detection (default = disable). |
option |
- |
disable |
||||||||
|
|
|
|||||||||||
|
hotspotter-attack |
Enable/disable hotspotter attack detection (default = disable). |
option |
- |
disable |
||||||||
|
|
|
|||||||||||
|
ht-40mhz-intolerance |
Enable/disable HT 40 MHz intolerance detection (default = disable). |
option |
- |
disable |
||||||||
|
|
|
|||||||||||
|
ht-greenfield |
Enable/disable HT greenfield detection (default = disable). |
option |
- |
disable |
||||||||
|
|
|
|||||||||||
|
invalid-addr-combination |
Enable/disable invalid address combination detection (default = disable). |
option |
- |
disable |
||||||||
|
|
|
|||||||||||
|
invalid-mac-oui |
Enable/disable invalid MAC OUI detection. |
option |
- |
disable |
||||||||
|
|
|
|||||||||||
|
long-duration-attack |
Enable/disable long duration attack detection based on user configured threshold (default = disable). |
option |
- |
disable |
||||||||
|
|
|
|||||||||||
|
long-duration-thresh |
Threshold value for long duration attack detection (1000 - 32767 usec, default = 8200). |
integer |
Minimum value: 1000 Maximum value: 32767 |
8200 |
||||||||
|
malformed-association |
Enable/disable malformed association request detection (default = disable). |
option |
- |
disable |
||||||||
|
|
|
|||||||||||
|
malformed-auth |
Enable/disable malformed auth frame detection (default = disable). |
option |
- |
disable |
||||||||
|
|
|
|||||||||||
|
malformed-ht-ie |
Enable/disable malformed HT IE detection (default = disable). |
option |
- |
disable |
||||||||
|
|
|
|||||||||||
|
name |
WIDS profile name. |
string |
Maximum length: 35 |
|
||||||||
|
netstumbler |
Enable/disable netstumbler detection (default = disable). |
option |
- |
disable |
||||||||
|
|
|
|||||||||||
|
netstumbler-thresh |
The threshold value for netstumbler. |
integer |
Minimum value: 1 Maximum value: 65100 |
5 |
||||||||
|
netstumbler-time |
Detection Window Period. |
integer |
Minimum value: 1 Maximum value: 120 |
30 |
||||||||
|
null-ssid-probe-resp |
Enable/disable null SSID probe response detection (default = disable). |
option |
- |
disable |
||||||||
|
|
|
|||||||||||
|
omerta-attack |
Enable/disable omerta attack detection (default = disable). |
option |
- |
disable |
||||||||
|
|
|
|||||||||||
|
overflow-ie |
Enable/disable overflow IE detection (default = disable). |
option |
- |
disable |
||||||||
|
|
|
|||||||||||
|
probe-flood |
Enable/disable probe flood detection (default = disable). |
option |
- |
disable |
||||||||
|
|
|
|||||||||||
|
probe-flood-thresh |
The threshold value for probe flood. |
integer |
Minimum value: 1 Maximum value: 65100 |
30 |
||||||||
|
probe-flood-time |
Detection Window Period. |
integer |
Minimum value: 1 Maximum value: 120 |
1 |
||||||||
|
pspoll-flood |
Enable/disable pspoll flood detection (default = disable). |
option |
- |
disable |
||||||||
|
|
|
|||||||||||
|
pspoll-flood-thresh |
The threshold value for pspoll flood. |
integer |
Minimum value: 1 Maximum value: 65100 |
30 |
||||||||
|
pspoll-flood-time |
Detection Window Period. |
integer |
Minimum value: 1 Maximum value: 120 |
1 |
||||||||
|
pwsave-dos-attack |
Enable/disable power save DOS attack detection (default = disable). |
option |
- |
disable |
||||||||
|
|
|
|||||||||||
|
reassoc-flood |
Enable/disable reassociation flood detection (default = disable). |
option |
- |
disable |
||||||||
|
|
|
|||||||||||
|
reassoc-flood-thresh |
The threshold value for reassociation flood. |
integer |
Minimum value: 1 Maximum value: 65100 |
30 |
||||||||
|
reassoc-flood-time |
Detection Window Period. |
integer |
Minimum value: 1 Maximum value: 120 |
10 |
||||||||
|
risky-encryption |
Enable/disable Risky Encryption detection (default = disable). |
option |
- |
disable |
||||||||
|
|
|
|||||||||||
|
rts-flood |
Enable/disable rts flood detection (default = disable). |
option |
- |
disable |
||||||||
|
|
|
|||||||||||
|
rts-flood-thresh |
The threshold value for rts flood. |
integer |
Minimum value: 1 Maximum value: 65100 |
30 |
||||||||
|
rts-flood-time |
Detection Window Period. |
integer |
Minimum value: 1 Maximum value: 120 |
10 |
||||||||
|
sensor-mode |
Scan nearby WiFi stations (default = disable). |
option |
- |
disable |
||||||||
|
|
|
|||||||||||
|
spoofed-deauth |
Enable/disable spoofed de-authentication attack detection (default = disable). |
option |
- |
disable |
||||||||
|
|
|
|||||||||||
|
unencrypted-valid |
Enable/disable unencrypted valid detection (default = disable). |
option |
- |
disable |
||||||||
|
|
|
|||||||||||
|
valid-client-misassociation |
Enable/disable valid client misassociation detection (default = disable). |
option |
- |
disable |
||||||||
|
|
|
|||||||||||
|
valid-ssid-misuse |
Enable/disable valid SSID misuse detection (default = disable). |
option |
- |
disable |
||||||||
|
|
|
|||||||||||
|
weak-wep-iv |
Enable/disable weak WEP IV (Initialization Vector) detection (default = disable). |
option |
- |
disable |
||||||||
|
|
|
|||||||||||
|
wellenreiter |
Enable/disable wellenreiter detection (default = disable). |
option |
- |
disable |
||||||||
|
|
|
|||||||||||
|
wellenreiter-thresh |
The threshold value for wellenreiter. |
integer |
Minimum value: 1 Maximum value: 65100 |
5 |
||||||||
|
wellenreiter-time |
Detection Window Period. |
integer |
Minimum value: 1 Maximum value: 120 |
30 |
||||||||
|
windows-bridge |
Enable/disable windows bridge detection (default = disable). |
option |
- |
disable |
||||||||
|
|
|
|||||||||||
|
wireless-bridge |
Enable/disable wireless bridge detection (default = disable). |
option |
- |
disable |
||||||||
|
|
|
|||||||||||
|
wpa-ft-attack |
Enable/disable WPA FT attack detection (default = disable). |
option |
- |
disable |
||||||||
|
|
|
|||||||||||