385| Wireless Intrusion Prevention DellPowerConnect W- Series ArubaOS 6.2 | User Guide
(host) #wms import-db database <file>
The wms reint-db command reinitializes the WMS database. Note that this command does not make an automatic
backupo f the currentdatabase.
(host) #wms reint-db
Understanding Cl ient Blacklisting
Whena client is blacklisted in the Dell system, the client is not allowed to associ ate with any AP in the network for
a specified amount of time. If a client is connected to the network wheni t is blacklisted,a deauthenticatio n
message is sent to force the client to disconnect. While blacklisted,the client cannot associat e with another SSID in
the network.
The controllerretains the client blacklist in the user database, so the information is not lost if the controller reboots.
Whenyou i mport or export the controller’suser database, the client blacklist wi llbe exported or i mported as well.

Methods o f Blacklisting

Thereare several ways in whic h a client can be blacklisted in the Dell system:
lYou can manuallyblacklist a specific c lient.See "Blacklisting Manually" on page 385 for more information.
lA client fails to successfully authenticate for a configured numbero f times for a specified authentication method.
The client is automatically blacklisted. See "Blacklistingby A uthentication Failure " on page 386 for more
information.
lA DoS or man in the middle (MITM) attack has been launched in the network. Detection of these attacks can
cause the immediate blacklisting of a client. See "EnablingA ttack Blacklisting" on page 386 for more information.
lAn externalapplicatio n or appliancet hat provides network services, such as virus protection or intrusion
detection, can blacklist a client andsend the blacklisting information to the controller via an XML API server.
Whenthe controller receives the client blacklist request fromthe server, it blacklists the client, logs an event, and
sends an SNMP trap.
See ExternalServices Interface on page 74 8 for more information.
NOTE:The External Services Interface feature require the Policy Enforcement Firewall Next Generation (PEFNG) license installed in
thecontroller.

Blacklisting Man ually

Thereare several reasons why you may choose to blacklist a client. For example, you can enabledifferent Dell
intrusion detection system (IDS) features that detect suspicious activities, such as MAC address spoofing or DoS
attacks. Whent hese activities are detected, an event is logged and an SNMP trap is sent wi th the client
information. To blacklist a client, you need to know its MAC address.
To manuallyblacklist a client via the WebUI:
1. N avigate to the Monitoring > Controller > Clients page.
2. Select the client to be blacklisted and click the Blacklist button.
To clear the entireclient blacklist using the WebUI:
1. N avigate to the Monitoring > Controller > Clients page.
2. Click Remove A ll from Blacklist.
To manuallyblacklist a client via the command-line interface, access the CLI in config mode and issue the following
command:
stm add-blacklist-client <macaddr>