cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
532
Views
0
Helpful
3
Replies

Cat9800 aWIPS alarms in DNAC

KevinR99
Level 1
Level 1

Hi

We have a Cat9800 controller with aWIPs enabled and it is sending alarms to a DNAC appliance.  I am seeing quite a lot of alarms that, if they are real, would suggest we have an inordinate number of Wifi attackers in our office.  The most frequent alarms are

Block Ack flood

Authentication floods

Targeted Deauthentication

Association flood

I really can't believe these are real events.

Has anyone deployed aWIPs on 9800's and seen similar results?

Thanks, Kev.

3 Replies 3

Hi

 I used to play with wIPS and I saw false alarms all the time. To be honest, wIPS is one the most unsuccessful  solution I ever see in my life.

ammahend
VIP
VIP

Arshad Safrulla
VIP Alumni
VIP Alumni

Below are mostly RF related attacks where mitigation is very limited or not possible. Description for all the possible alerts are listed in the below article.

https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-1/config-guide/b_wl_17_11_cg/b_wl_17_11_cg_chapter_010001100.html

I would not agree that the aWIPS is not a successful product. It has it's own use cases, for example if a client is complaining about connectivity issues you can have a look at aWIPS alerts from that AP or the AP's in the vicinity to check whether there is any targeted deauths. Most importantly Rogue detection and containment is also part of aWIPS (Some countries may have legal complications using this feature, take caution) aWIPS will provide you a holistic view of and threat landscape at RF level. With the enterprises moving to complete wireless connectivity, this is one of the must features to have. As @ammahend mentioned there could be lot of false positives as wireless medium itself is not restricted and an attacked with a directional antenna with enough gain could trigger deauth's in your wireless environment may be sitting meters away.

Review Cisco Networking for a $25 gift card