<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IDS Signature attack detected on a Wireless Network in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/ids-signature-attack-detected-on-a-wireless-network/m-p/783266#M29458</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am running MFP on my WLC. &lt;/P&gt;&lt;P&gt;I recieved the same error message with MFP anomolies (NO MIC).  Under wireless peotecion policies I have MFP enabled.  Should I disable MFP and change it to AP authentication? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 05 Oct 2007 18:46:31 GMT</pubDate>
    <dc:creator>derek.james</dc:creator>
    <dc:date>2007-10-05T18:46:31Z</dc:date>
    <item>
      <title>IDS Signature attack detected on a Wireless Network</title>
      <link>https://community.cisco.com/t5/wireless/ids-signature-attack-detected-on-a-wireless-network/m-p/783262#M29454</link>
      <description>&lt;P&gt;Hello all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a little Wireless netwok ( 1 WLC 2200 and 6 AP 1100 series )and since few days I have the following message :" IDS Signature attack detected. Signature Type:Standard, Name: Assoc flood, Description: Association Request flood, Track:per-signature, Detecting AP Name: AP3, Radio Type: 802.11b/g, Preced:4,Hits: 50, Channel: 6, srcMac: 00:16:6F:49:C6:8A " and don't know how to resolve !&lt;/P&gt;&lt;P&gt;Help is welcome !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 03 Jul 2021 21:02:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ids-signature-attack-detected-on-a-wireless-network/m-p/783262#M29454</guid>
      <dc:creator>joel.gabriel</dc:creator>
      <dc:date>2021-07-03T21:02:57Z</dc:date>
    </item>
    <item>
      <title>Re: IDS Signature attack detected on a Wireless Network</title>
      <link>https://community.cisco.com/t5/wireless/ids-signature-attack-detected-on-a-wireless-network/m-p/783263#M29455</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What version of code are you running on the 2002? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 May 2007 11:13:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ids-signature-attack-detected-on-a-wireless-network/m-p/783263#M29455</guid>
      <dc:creator>da.beaver</dc:creator>
      <dc:date>2007-05-09T11:13:10Z</dc:date>
    </item>
    <item>
      <title>Re: IDS Signature attack detected on a Wireless Network</title>
      <link>https://community.cisco.com/t5/wireless/ids-signature-attack-detected-on-a-wireless-network/m-p/783264#M29456</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I just received the following from TAC today:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In regards to the "IDS 'Disassoc flood' Signature attack detected on AP" log, please refer to following bug:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Title: &lt;/P&gt;&lt;P&gt;IDS:AP impersonation alerts against own AP mac address&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Symptom:&lt;/P&gt;&lt;P&gt;WLC is reporting AP impersonation alerts for the same MAC address of the AP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tha MAC address corresponds to the first WLAN configured&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AP Impersonation with MAC 'xx:xx:xx:xx:xx:xx' is detected by authenticated AP 'xx:xx:xx:xx:xx:xx' on '802.11b/g' radio and Slot ID '0'. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The event can be triggered if AP can hear itself due to RF conditions, and there is no AP authentication enabled in controllers&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Workaround:&lt;/P&gt;&lt;P&gt;Enable "AP Authentication feature" and trigger set to 2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/cgi-bin/Support/Bugtool/onebug.pl?bugid=CSCsg44344" target="_blank"&gt;http://www.cisco.com/cgi-bin/Support/Bugtool/onebug.pl?bugid=CSCsg44344&lt;/A&gt; (Requires CCO Login)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please go into your controller GUI&amp;gt;&amp;gt;Security&amp;gt;&amp;gt;Wireless Protection&lt;/P&gt;&lt;P&gt;Policies&amp;gt;&amp;gt;AP Authentication/MFP and for Protection Type set that to AP&lt;/P&gt;&lt;P&gt;Authentication and trigger set to 2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 May 2007 20:27:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ids-signature-attack-detected-on-a-wireless-network/m-p/783264#M29456</guid>
      <dc:creator>mghcisco</dc:creator>
      <dc:date>2007-05-09T20:27:51Z</dc:date>
    </item>
    <item>
      <title>Re: IDS Signature attack detected on a Wireless Network</title>
      <link>https://community.cisco.com/t5/wireless/ids-signature-attack-detected-on-a-wireless-network/m-p/783265#M29457</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Wow, I was also getting these alerts.  I just implemented the suggestion and will see how it goes.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 May 2007 21:41:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ids-signature-attack-detected-on-a-wireless-network/m-p/783265#M29457</guid>
      <dc:creator>isdept</dc:creator>
      <dc:date>2007-05-09T21:41:39Z</dc:date>
    </item>
    <item>
      <title>Re: IDS Signature attack detected on a Wireless Network</title>
      <link>https://community.cisco.com/t5/wireless/ids-signature-attack-detected-on-a-wireless-network/m-p/783266#M29458</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am running MFP on my WLC. &lt;/P&gt;&lt;P&gt;I recieved the same error message with MFP anomolies (NO MIC).  Under wireless peotecion policies I have MFP enabled.  Should I disable MFP and change it to AP authentication? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Oct 2007 18:46:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ids-signature-attack-detected-on-a-wireless-network/m-p/783266#M29458</guid>
      <dc:creator>derek.james</dc:creator>
      <dc:date>2007-10-05T18:46:31Z</dc:date>
    </item>
  </channel>
</rss>

