<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Alarm fatigue with Threat Active / External Honeypot in WIPS / RADAR in ExtremeCloud IQ- Site Engine Management Center</title>
    <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/alarm-fatigue-with-threat-active-external-honeypot-in-wips-radar/m-p/17520#M527</link>
    <description>Hello folks,&lt;BR /&gt;
&lt;BR /&gt;
I have a sprawling wireless network that covers a lot of acres in town. Aside from the insanely high number of guest wireless users, I also run alongside a lot of public buildings that have their own WiFi networks (such as a large car lot).&lt;BR /&gt;
&lt;BR /&gt;
I seem to have a nagging collection of threats for "external honeypots". Which is OK if the device lingers. But I seem to get an alert for drive-by users. And I know sometimes a user requesting a network can result in a false detection. In other words, they fire open their laptop and Windows says "is there a dlink SSID in the house?" which then results in an External Honeypot message of "there is a dlink SSID!". I also seem so pick up a lot of cars from the car lot that have their own SSID's for the driver, passengers, and mechanics.&lt;BR /&gt;
&lt;BR /&gt;
My question is, how do I make these threats self-clear? I have a bunch where the first/last seen is all in the same time/minutes/seconds? I went into XMC and edited the Alarm Definition. Then under Other Options I checked the box for Cleared by Alarms "Threat Inactive". And then I also tried checking "No Curent Alarm". But neither one seemed to clear up all my old alarms. I still need to manually right-click and clear selected alarm.&lt;BR /&gt;
&lt;BR /&gt;</description>
    <pubDate>Tue, 15 May 2018 18:05:00 GMT</pubDate>
    <dc:creator>Steve_Ballantyn</dc:creator>
    <dc:date>2018-05-15T18:05:00Z</dc:date>
    <item>
      <title>Alarm fatigue with Threat Active / External Honeypot in WIPS / RADAR</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/alarm-fatigue-with-threat-active-external-honeypot-in-wips-radar/m-p/17520#M527</link>
      <description>Hello folks,&lt;BR /&gt;
&lt;BR /&gt;
I have a sprawling wireless network that covers a lot of acres in town. Aside from the insanely high number of guest wireless users, I also run alongside a lot of public buildings that have their own WiFi networks (such as a large car lot).&lt;BR /&gt;
&lt;BR /&gt;
I seem to have a nagging collection of threats for "external honeypots". Which is OK if the device lingers. But I seem to get an alert for drive-by users. And I know sometimes a user requesting a network can result in a false detection. In other words, they fire open their laptop and Windows says "is there a dlink SSID in the house?" which then results in an External Honeypot message of "there is a dlink SSID!". I also seem so pick up a lot of cars from the car lot that have their own SSID's for the driver, passengers, and mechanics.&lt;BR /&gt;
&lt;BR /&gt;
My question is, how do I make these threats self-clear? I have a bunch where the first/last seen is all in the same time/minutes/seconds? I went into XMC and edited the Alarm Definition. Then under Other Options I checked the box for Cleared by Alarms "Threat Inactive". And then I also tried checking "No Curent Alarm". But neither one seemed to clear up all my old alarms. I still need to manually right-click and clear selected alarm.&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Tue, 15 May 2018 18:05:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/alarm-fatigue-with-threat-active-external-honeypot-in-wips-radar/m-p/17520#M527</guid>
      <dc:creator>Steve_Ballantyn</dc:creator>
      <dc:date>2018-05-15T18:05:00Z</dc:date>
    </item>
  </channel>
</rss>

