Specifications
IDS and DoS Alerts
RoamAbout Mobility System Software Configuration Guide 22-15
Disallowed Devices or SSIDs
YoucanconfigurethefollowingtypesofliststoexplicitlyallowspecificdevicesorSSIDs:
• PermittedSSIDlist—MSSgeneratesamessageifanSSIDthatisnotonthelistisdetected.
• Permittedvendorlist—MSSgeneratesamessageifanAPorwirelessclientwithanOUIthat
isnotonthe
listisdetected.
•Clientblacklist—MSSpreventsclientsonthelistfromaccessingthenetworkthroughaRAS.
IftheclientisplacedontheblacklistdynamicallybyMSSduetoanassociation,reassociation
ordisassociationflood,MSSgeneratesalogmessage.
Bydefault,theselistsareemptyandall
SSIDs,vendors,andclientsareallowed.Formore
information,see“SummaryofRogueDetectionFeatures”onpage 22‐5.
Displaying Statistics Counters
TodisplayIDSandDoSstatisticscounters,usetheshowrfdetectcounterscommands.(See
“DisplayingStatisticsCounters”onpage 22 ‐15.)
IDS Log Message Examples
Table 22‐2showsexamplesofthelogmessagesgeneratedbyIDS.
Table 22-2 IDS and DoS Log Messages
Message Type Example Log Message
Probe message flood Client aa:bb:cc:dd:ee:ff is sending probe message flood.
Seen by AP on radio 1 on channel 11 with RSSI -53.
Authentication message flood Client aa:bb:cc:dd:ee:ff is sending authentication message flood.
Seen by AP on radio 1 on channel 11 with RSSI -53.
Null data message flood Client aa:bb:cc:dd:ee:ff is sending null data message flood.
Seen by AP on radio 1 on channel 11 with RSSI -53.
Management frame 6 flood Client aa:bb:cc:dd:ee:ff is sending rsvd mgmt frame 6 message flood.
Seen by AP on radio 1 on channel 11 with RSSI -53.
Management frame 7 flood Client aa:bb:cc:dd:ee:ff is sending rsvd mgmt frame 7 message flood.
Seen by AP on radio 1 on channel 11 with RSSI -53.
Management frame D flood Client aa:bb:cc:dd:ee:ff is sending rsvd mgmt frame D message flood.
Seen by AP on radio 1 on channel 11 with RSSI -53.
Management frame E flood Client aa:bb:cc:dd:ee:ff is sending rsvd mgmt frame E message flood.
Seen by AP on radio 1 on channel 11 with RSSI -53.
Management frame F flood Client aa:bb:cc:dd:ee:ff is sending rsvd mgmt frame F message flood.
Seen by AP on radio 1 on channel 11 with RSSI -53.
Associate request flood Client aa:bb:cc:dd:ee:ff is sending associate request flood on AP
Reassociate request flood Client aa:bb:cc:dd:ee:ff is sending re-associate request flood on AP