worried about one AP recieving large NAV fields for weeks ?

Unanswered Question
Apr 2nd, 2009
User Badges:


I have lan controllers and cisco WCS. One ap is recieving this message..

The AP '00:**:**:**:**:**' with protocol '802.11b/g' on Controller '**.***.***.**' received a message with a large NAV field. This is most likely a malicious denial of service attack.

(removed the numbers replaced with *)

now there are 4 pages of the same instance on this one AP.

I dont have any more information.. i.e it does not tell me on WCS what the mac is of the machine doing this (if there is one) nor does it tell me on the lan controllers.

how do i detect this problem and identify

many thanks


  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
dennischolmes Thu, 04/02/2009 - 06:24
User Badges:
  • Gold, 750 points or more

I would first verify that the actual signal exists. If you have access to Airmagnet WiFi Analyzer you will get all the information you need and have the ability to locate the device doing this. If not, contract a good Cisco wireless partner that does have this or a similar application to verify the actual existence of the problem. It could be a code bug but I haven't seen it myself and I don't see any info in the bug tool pertaining to it.


This Discussion



Trending Topics - Security & Network