×

Warning message

  • Cisco Support Forums is in Read Only mode while the site is being migrated.
  • Cisco Support Forums is in Read Only mode while the site is being migrated.
Rasika Nayanajith Tue, 09/30/2014 - 21:02
User Badges:
  • Purple, 4500 points or more
  • Cisco Designated VIP,

    2017 Wireless

Hi

If you enable this feature a wireless client will be excluded from the network for a configured amount of time.

<span style="font-family:courier new,courier,monospace;">1. Excessive 802.11 Association Failures&mdash;Clients are excluded on the sixth 802.11 association attempt, after five consecutive failures.<br />2. Excessive 802.11 Authentication Failures&mdash;Clients are excluded on the sixth 802.11 authentication attempt, after five consecutive failures.<br />3. Excessive 802.1X Authentication Failures&mdash;Clients are excluded on the fourth 802.1X authentication attempt, after three consecutive failures.<br />4. IP Theft or IP Reuse&mdash;Clients are excluded if the IP address is already assigned to another device.<br />5. Excessive Web Authentication Failures&mdash;Clients are excluded on the fourth web authentication attempt, after three consecutive failures.</span>

If you do not want to client to be excluded (eg: sometime genuine user get excluded if he enter the wrong password more than 5 times) in those circumstances, you can disabled it.

HTH

Rasika

**** Pls rate all useful responses ****

nareshjohal Wed, 10/01/2014 - 16:48
User Badges:

Thanks for the response.  I understand how it works I just wondered what the best practice was and why. 

Rasika Nayanajith Wed, 10/01/2014 - 16:53
User Badges:
  • Purple, 4500 points or more
  • Cisco Designated VIP,

    2017 Wireless

Best practices  is unique to a given environment.  If you have very controlled wifi user base, I would turn that off. 

If you  have large environment where users bring their own devices & connect, I would keep turn it on (to alerted who is trying to detect few sorts  of threats)

Pls do not forget to rate our responses if you find that is useful.

 

HTH

Rasika

 

Actions

This Discussion

 

 

Trending Topics - Security & Network