<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IDS Signature Attack in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/ids-signature-attack/m-p/4545010#M237992</link>
    <description>&lt;P&gt;Its all depends on what you using 802.1x then ISE can take some action here and block the client.&lt;/P&gt;</description>
    <pubDate>Thu, 03 Feb 2022 17:47:50 GMT</pubDate>
    <dc:creator>balaji.bandi</dc:creator>
    <dc:date>2022-02-03T17:47:50Z</dc:date>
    <item>
      <title>IDS Signature Attack</title>
      <link>https://community.cisco.com/t5/wireless/ids-signature-attack/m-p/4545004#M237991</link>
      <description>&lt;P&gt;All,&lt;/P&gt;&lt;P&gt;what happens when an IDS Signature Attack is detected? What is the response of the Wireless Controller? Does this lock out all users on that AP for a time period or just that individual user for a period of time?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Thu, 03 Feb 2022 17:42:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ids-signature-attack/m-p/4545004#M237991</guid>
      <dc:creator>Lumbee</dc:creator>
      <dc:date>2022-02-03T17:42:19Z</dc:date>
    </item>
    <item>
      <title>Re: IDS Signature Attack</title>
      <link>https://community.cisco.com/t5/wireless/ids-signature-attack/m-p/4545010#M237992</link>
      <description>&lt;P&gt;Its all depends on what you using 802.1x then ISE can take some action here and block the client.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Feb 2022 17:47:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ids-signature-attack/m-p/4545010#M237992</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-02-03T17:47:50Z</dc:date>
    </item>
    <item>
      <title>Re: IDS Signature Attack</title>
      <link>https://community.cisco.com/t5/wireless/ids-signature-attack/m-p/4545013#M237993</link>
      <description>&lt;P&gt;BB,&lt;/P&gt;&lt;P&gt;thanks for the quick response. Just to be clear this IDS Signature Attack is 802.1x based?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Feb 2022 17:50:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ids-signature-attack/m-p/4545013#M237993</guid>
      <dc:creator>Lumbee</dc:creator>
      <dc:date>2022-02-03T17:50:05Z</dc:date>
    </item>
    <item>
      <title>Re: IDS Signature Attack</title>
      <link>https://community.cisco.com/t5/wireless/ids-signature-attack/m-p/4545151#M237998</link>
      <description>&lt;P&gt;Hi Lumbee,&lt;/P&gt;
&lt;P&gt;When it comes to wireless world there are very few intrusion attacks which can be contained automatically. For example if someone is advertising a rogue SSID in the vicinity you can configure the WLC to perform a legitimate deauth attack to contain the rogue AP. If a rogue AP seen on your LAN it can follow the same suit to contain it. If there is a client who is trying to spoof a MAC address of a legitimate client you can block the access to MAC address, but this will impact the legitimate client as well, the list goes on.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-1/config-guide/b_wl_17_11_cg/b_wl_17_11_cg_chapter_010001100.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-1/config-guide/b_wl_17_11_cg/b_wl_17_11_cg_chapter_010001100.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But however most of the attacks which happens at the RF level cannot be contained, rather we can configure the wireless infra to identify these attacks and alert us. based on the severity of the attack then as per the defined security policy you may have to act manually. There are many attacks which can be categorized as DOS attacks which can be identified by wireless infra (probe floods, beacon floods, CTS/RTS floods etc.) but from your wireless infra I do not think you can automate to contain the attacks. As I said before this requires human to interact manually and act.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It is always recommended to have visibility in to your wireless infra as this will provide you with required forensics in case of an attack. However due to the medium behavior only certain attacks can be mitigated or contained, and others can be only identified.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Feb 2022 22:27:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ids-signature-attack/m-p/4545151#M237998</guid>
      <dc:creator>Arshad Safrulla</dc:creator>
      <dc:date>2022-02-03T22:27:54Z</dc:date>
    </item>
    <item>
      <title>Re: IDS Signature Attack</title>
      <link>https://community.cisco.com/t5/wireless/ids-signature-attack/m-p/4545211#M237999</link>
      <description>&lt;P&gt;Since SSID is publicly available, there may be many attacks on SSID, that need to be verified based on the information generated on the Wireless controller, if you have a strong authentication system in place, these attacks can be blocked for while (if the system in place).&lt;/P&gt;
&lt;P&gt;some reference how the logs looks like :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wireless-lan-wlan/69366-controller-ids-sig.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wireless-lan-wlan/69366-controller-ids-sig.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Feb 2022 01:22:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ids-signature-attack/m-p/4545211#M237999</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-02-04T01:22:10Z</dc:date>
    </item>
  </channel>
</rss>

