cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1260
Views
0
Helpful
4
Replies

Any way to shut off WLC syslog %APF-4-ROGUE_AP_ADD_FAILED?

MICHAEL CIULLA
Level 1
Level 1

Hello,

Does anyone know of a way to shut off syslog traffic for "%APF-4-ROGUE_AP_ADD_FAILED" other than by changing the WLC syslog level?

We need to keep that level (warning level 4) in order to view important warnings.  The message noted above is 70% of WLC syslog traffic...way too much.

Mike Ciulla

4 Replies 4

Dirk Woellhaf
Level 1
Level 1

Hi,

did you try to filter it on your Syslog-Receiver? Maybe the easiest way to do it!

Dirk

regards, Dirk (Please rate if helpful)

Hi Dirk,

Your idea is certainly a good one, and may be my only choice, but I'm trying to avoid the network traffic.  We have a sprawling campus system the size of a small city and there are lots of other wireless about, so I get about 20k/hr of just this specific log, and mutiply that by 3 for each of the syslog servers.  ugh.

Also, its too much effort to mark all APs as known friendlies per controller, either, which would be another way to reduce this spam alerting.

Hi,

if you're using WCS, which I hope you do, you can specify "Rogue Policies" which should classify the rogues automatically and doing so, reduce your "spam".

You can find it under "Controller Template Launch Pad -> Security -> Rogue AP Rules"

Unfortunatley, this will not work every time. Have some issues here in my setup as well.

Dirk

regards, Dirk (Please rate if helpful)

Hi,

Yeah, we tried that too with WCS. We can classify malicious (unknown AP using our SSIDs) and friendly (known APs another department that we are merging with), but not unclassified, which is where most of them sit.  The controllers max out with rogues and dump all the "add failed" spam logs. Looks like we will just filter syslog servers after it traverses the network, as you mentioned.  I guess 20k/hr is not that heavy anyway, but it does tie up a some WLC processing power.  Was thinking the spam could be dumped right at the controller.

Review Cisco Networking for a $25 gift card