cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1543
Views
0
Helpful
1
Replies

Root causing the source of "IDS 'Auth flood' Signature attacks"

Muhammed Adnan
Level 4
Level 4

Hello Experts, 

 

I have a network of over 100 APs with WLC running code 8.6.

Every day consistently I tend to see "IDS 'Auth flood' Signature attacks" through different APs. 

Would not want to ignore it for long. 

What are the possible reason for this alarm to get triggered? What are the false positives and the means to root cause the exact reason of this alarm?

 

IDS auth flood signature attacks.png

1 Reply 1

No reply to this for a long time, but I wanted to share that I have the same issue and we have 5000 APs... You can imagine the amount of alerts we get, right?  

I hope they find a solution to this, as I've seen other people with the same post on here...

Review Cisco Networking products for a $25 gift card