Specifications

2-99
Cisco IOS Command Reference for Cisco Aironet Access Points and Bridges
0L-24115-01
Chapter 2 Cisco IOS Commands for Access Points and Bridges
dot11 auto-immune
dot11 auto-immune
Use the dot11 auto-immune command to enable or disable protection from Denial of Service (DoS)
attacks. This feature protects against auto-immune attacks on the AP.
dot11 auto-immune {enable | disable}
Syntax Description
Defaults This feature is disabled by default.
Command History
Usage Guidelines A potential attacker can use specially crafted packets to mislead the Intrusion Detection System (IDS)
into treating a legitimate client as an attacker. It causes the controller to disconnect this legitimate client
and launch a DoS attack. The auto-immune feature, when enabled, is designed to protect against such
attacks. However, conversations using Cisco 792x phones might be interrupted intermittently when the
auto-immune feature is enabled. If you experience frequent disruptions when using 792x phones, you
might want to disable this feature.
Examples This example shows how to enable the auto-immune mode.
AP(config)# dot11 auto-immune enable
enable Enables the auto-immune feature.
disable Disables the auto-immune feature.
Release Modification
12.4(25d)JA This command was introduced.