Prevent wireless PSK brute force attacks or configure password error limit function
This function is not enabled by default. The required commands are as follows:
wlan password-failure-limit enable
Parameters that can be included:
detection-period: detection cycle
failure-threshold: threshold for password error count
Once enabled, if the number of failed password attempts reaches the upper limit within the specified detection cycle, the client will be immediately added to the dynamic denylist.
Use the command display wlan blacklist dynamic to view
Use the command wlan dynamic-blacklist lifetime xxx to modify the dynamic denylist duration. The default is 300 seconds.
Actual testing shows:
Before configuring commands, if the terminal password is entered incorrectly, the prompt password error will be displayed.
After configuring commands, multiple incorrect inputs will trigger the prompt unable to join.
Note that entering an incorrect password or being added to the denylist will not generate log records or echo messages.
Currently, the reason for terminal going offline or being added to the denylist can only be viewed under the AC probe view using the command display system internal wlan client history-record mac-address xx // xx is the terminal MAC address.
The commands are as follows
wlan password-failure-limit enable