<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AP/Client Flood, Single device packet flood in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/ap-client-flood-single-device-packet-flood/m-p/5485188#M296370</link>
    <description>&lt;P&gt;There's no way you can really confirm whether the devices are flooding maliciously or not without tracking them down.&lt;BR /&gt;It could be anything from poorly designed IOT devices to bad drivers, or someone attempting a malicious attack.&lt;/P&gt;&lt;P&gt;Do you have any AP's on the same network or broadcasting the same SSID that are not part of this Meraki dashboard?&lt;BR /&gt;Is it always the same AP that's detecting it? If so, could be worth giving it a reboot.&lt;/P&gt;&lt;P&gt;A few threads that provide some more information and other people's experience:&lt;BR /&gt;&lt;A href="https://community.meraki.com/t5/Full-Stack-Network-Wide/Packet-floods-detected-by-AirMarshal/td-p/10132" target="_blank"&gt;Packet floods detected by AirMarshal - The Meraki Community&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://community.meraki.com/t5/Wireless-LAN/Mr34-packet-flood-issues/td-p/27394" target="_blank"&gt;Solved: Mr34 packet flood issues - The Meraki Community&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://documentation.meraki.com/MR/Monitoring_and_Reporting/Air_Marshal#Packet_Floods" target="_blank" rel="nofollow noopener noreferrer"&gt;Air Marshal - Cisco Meraki&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 03 Jan 2023 22:25:13 GMT</pubDate>
    <dc:creator>Brash</dc:creator>
    <dc:date>2023-01-03T22:25:13Z</dc:date>
    <item>
      <title>AP/Client Flood, Single device packet flood</title>
      <link>https://community.cisco.com/t5/wireless/ap-client-flood-single-device-packet-flood/m-p/5485187#M296369</link>
      <description>&lt;P&gt;The MAC addresses reported  are all non registered.  &lt;/P&gt;&lt;P&gt;Worked with support for a Packet capture and was led to believe it was a ring doorbell.&lt;/P&gt;&lt;P&gt;Asked the co tenant to turn off the door bell. &lt;/P&gt;&lt;P&gt;Issue exists still.&lt;/P&gt;&lt;P&gt;Has anyone seen  this similar issue?&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Jan 3 13:45:07&lt;/TD&gt;&lt;TD&gt;&lt;A href="https://n266.meraki.com/Freenome-HQ-wire/n/9w-D2a0c/manage/nodes/list#n=13803411301836" target="_blank" rel="noopener nofollow noreferrer"&gt;FN285-WAP2&lt;/A&gt;&lt;/TD&gt;&lt;TD&gt; &lt;/TD&gt;&lt;TD&gt; &lt;/TD&gt;&lt;TD&gt;&lt;SPAN&gt;AP / client flood&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD&gt;radio: 1, state: end, alarm_id: 6318  &lt;SPAN class=""&gt;&lt;A class="" href="https://n266.meraki.com/Freenome-HQ-wire/n/9w-D2a0c/manage/dashboard/event_log#" target="_blank" rel="noopener nofollow noreferrer"&gt;more »&lt;/A&gt;&lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Jan 3 13:45:00&lt;/TD&gt;&lt;TD&gt;&lt;A href="https://n266.meraki.com/Freenome-HQ-wire/n/9w-D2a0c/manage/nodes/list#n=13803411301836" target="_blank" rel="noopener nofollow noreferrer"&gt;FN285-WAP2&lt;/A&gt;&lt;/TD&gt;&lt;TD&gt; &lt;/TD&gt;&lt;TD&gt; &lt;/TD&gt;&lt;TD&gt;&lt;SPAN&gt;AP / client flood&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD&gt;packet: beacon, radio: 1, bssid: E2:CB:AC:90:4B:26  &lt;SPAN class=""&gt;&lt;A class="" href="https://n266.meraki.com/Freenome-HQ-wire/n/9w-D2a0c/manage/dashboard/event_log#" target="_blank" rel="noopener nofollow noreferrer"&gt;more »&lt;/A&gt;&lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Jan 3 13:44:57&lt;/TD&gt;&lt;TD&gt;&lt;A href="https://n266.meraki.com/Freenome-HQ-wire/n/9w-D2a0c/manage/nodes/list#n=13803411301836" target="_blank" rel="noopener nofollow noreferrer"&gt;FN285-WAP2&lt;/A&gt;&lt;/TD&gt;&lt;TD&gt; &lt;/TD&gt;&lt;TD&gt; &lt;/TD&gt;&lt;TD&gt;&lt;SPAN&gt;AP / client flood&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD&gt;radio: 1, state: end, alarm_id: 6317  &lt;SPAN class=""&gt;&lt;A class="" href="https://n266.meraki.com/Freenome-HQ-wire/n/9w-D2a0c/manage/dashboard/event_log#" target="_blank" rel="noopener nofollow noreferrer"&gt;more »&lt;/A&gt;&lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Jan 3 13:44:49&lt;/TD&gt;&lt;TD&gt;&lt;A href="https://n266.meraki.com/Freenome-HQ-wire/n/9w-D2a0c/manage/nodes/list#n=13803411301836" target="_blank" rel="noopener nofollow noreferrer"&gt;FN285-WAP2&lt;/A&gt;&lt;/TD&gt;&lt;TD&gt; &lt;/TD&gt;&lt;TD&gt; &lt;/TD&gt;&lt;TD&gt;&lt;SPAN&gt;AP / client flood&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD&gt;packet: probe_resp, radio: 1, bssid: EA:CB:AC:90:4B:26  &lt;SPAN class=""&gt;&lt;A class="" href="https://n266.meraki.com/Freenome-HQ-wire/n/9w-D2a0c/manage/dashboard/event_log#" target="_blank" rel="noopener nofollow noreferrer"&gt;more »&lt;/A&gt;&lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Jan 3 13:44:27&lt;/TD&gt;&lt;TD&gt;&lt;A href="https://n266.meraki.com/Freenome-HQ-wire/n/9w-D2a0c/manage/nodes/list#n=13803411301836" target="_blank" rel="noopener nofollow noreferrer"&gt;FN285-WAP2&lt;/A&gt;&lt;/TD&gt;&lt;TD&gt; &lt;/TD&gt;&lt;TD&gt; &lt;/TD&gt;&lt;TD&gt;&lt;SPAN&gt;Single device packet flood&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD&gt;radio: 1, state: end, alarm_id: 6316  &lt;SPAN class=""&gt;&lt;A class="" href="https://n266.meraki.com/Freenome-HQ-wire/n/9w-D2a0c/manage/dashboard/event_log#" target="_blank" rel="noopener nofollow noreferrer"&gt;more »&lt;/A&gt;&lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Jan 3 13:44:27&lt;/TD&gt;&lt;TD&gt;&lt;A href="https://n266.meraki.com/Freenome-HQ-wire/n/9w-D2a0c/manage/nodes/list#n=13803411301836" target="_blank" rel="noopener nofollow noreferrer"&gt;FN285-WAP2&lt;/A&gt;&lt;/TD&gt;&lt;TD&gt; &lt;/TD&gt;&lt;TD&gt; &lt;/TD&gt;&lt;TD&gt;&lt;SPAN&gt;AP / client flood&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD&gt;radio: 1, state: end, alarm_id: 6315  &lt;SPAN class=""&gt;&lt;A class="" href="https://n266.meraki.com/Freenome-HQ-wire/n/9w-D2a0c/manage/dashboard/event_log#" target="_blank" rel="noopener nofollow noreferrer"&gt;more »&lt;/A&gt;&lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Jan 3 13:44:26&lt;/TD&gt;&lt;TD&gt;&lt;A href="https://n266.meraki.com/Freenome-HQ-wire/n/9w-D2a0c/manage/nodes/list#n=13803411301836" target="_blank" rel="noopener nofollow noreferrer"&gt;FN285-WAP2&lt;/A&gt;&lt;/TD&gt;&lt;TD&gt; &lt;/TD&gt;&lt;TD&gt; &lt;/TD&gt;&lt;TD&gt;&lt;SPAN&gt;Single device packet flood&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD&gt;packet: probe_resp, device: EA:CB:AC:90:4B:26, radio: 1  &lt;SPAN class=""&gt;&lt;A class="" href="https://n266.meraki.com/Freenome-HQ-wire/n/9w-D2a0c/manage/dashboard/event_log#" target="_blank" rel="noopener nofollow noreferrer"&gt;more »&lt;/A&gt;&lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Jan 3 13:44:19&lt;/TD&gt;&lt;TD&gt;&lt;A href="https://n266.meraki.com/Freenome-HQ-wire/n/9w-D2a0c/manage/nodes/list#n=13803411301836" target="_blank" rel="noopener nofollow noreferrer"&gt;FN285-WAP2&lt;/A&gt;&lt;/TD&gt;&lt;TD&gt; &lt;/TD&gt;&lt;TD&gt; &lt;/TD&gt;&lt;TD&gt;&lt;SPAN&gt;AP / client flood&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD&gt;packet: beacon, radio: 1, bssid: 0A:8D:CB:71:42:DE  &lt;SPAN class=""&gt;&lt;A class="" href="https://n266.meraki.com/Freenome-HQ-wire/n/9w-D2a0c/manage/dashboard/event_log#" target="_blank" rel="noopener nofollow noreferrer"&gt;more »&lt;/A&gt;&lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Tue, 03 Jan 2023 21:56:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ap-client-flood-single-device-packet-flood/m-p/5485187#M296369</guid>
      <dc:creator>JED2021</dc:creator>
      <dc:date>2023-01-03T21:56:37Z</dc:date>
    </item>
    <item>
      <title>Re: AP/Client Flood, Single device packet flood</title>
      <link>https://community.cisco.com/t5/wireless/ap-client-flood-single-device-packet-flood/m-p/5485188#M296370</link>
      <description>&lt;P&gt;There's no way you can really confirm whether the devices are flooding maliciously or not without tracking them down.&lt;BR /&gt;It could be anything from poorly designed IOT devices to bad drivers, or someone attempting a malicious attack.&lt;/P&gt;&lt;P&gt;Do you have any AP's on the same network or broadcasting the same SSID that are not part of this Meraki dashboard?&lt;BR /&gt;Is it always the same AP that's detecting it? If so, could be worth giving it a reboot.&lt;/P&gt;&lt;P&gt;A few threads that provide some more information and other people's experience:&lt;BR /&gt;&lt;A href="https://community.meraki.com/t5/Full-Stack-Network-Wide/Packet-floods-detected-by-AirMarshal/td-p/10132" target="_blank"&gt;Packet floods detected by AirMarshal - The Meraki Community&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://community.meraki.com/t5/Wireless-LAN/Mr34-packet-flood-issues/td-p/27394" target="_blank"&gt;Solved: Mr34 packet flood issues - The Meraki Community&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://documentation.meraki.com/MR/Monitoring_and_Reporting/Air_Marshal#Packet_Floods" target="_blank" rel="nofollow noopener noreferrer"&gt;Air Marshal - Cisco Meraki&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jan 2023 22:25:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ap-client-flood-single-device-packet-flood/m-p/5485188#M296370</guid>
      <dc:creator>Brash</dc:creator>
      <dc:date>2023-01-03T22:25:13Z</dc:date>
    </item>
  </channel>
</rss>

