worried about one AP recieving large NAV fields for weeks ?

Unanswered Question
Apr 2nd, 2009


I have lan controllers and cisco WCS. One ap is recieving this message..

The AP '00:**:**:**:**:**' with protocol '802.11b/g' on Controller '**.***.***.**' received a message with a large NAV field. This is most likely a malicious denial of service attack.

(removed the numbers replaced with *)

now there are 4 pages of the same instance on this one AP.

I dont have any more information.. i.e it does not tell me on WCS what the mac is of the machine doing this (if there is one) nor does it tell me on the lan controllers.

how do i detect this problem and identify

many thanks


I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
dennischolmes Thu, 04/02/2009 - 06:24

I would first verify that the actual signal exists. If you have access to Airmagnet WiFi Analyzer you will get all the information you need and have the ability to locate the device doing this. If not, contract a good Cisco wireless partner that does have this or a similar application to verify the actual existence of the problem. It could be a code bug but I haven't seen it myself and I don't see any info in the bug tool pertaining to it.


This Discussion



Trending Topics - Security & Network