I recieved the follwoing message from WCS but not sure what it means.
IDS 'Auth flood' Signature attack detected on AP 'POP_10' protocol '802.11b/g' on Controller '10.x.x.x'. The Signature description is 'Authentication Request flood', with precedence '5'. The attacker's mac address is '00:e2:f0:f0:12:3e', channel number is '6', and the number of detections is '30'.
I tried searching through the forums and cisco.com but unable to find info.
Transferring Crash file from standby: Login to the Active WLC in HA.
From CLI: (Cisco Controller) >transfer upload datatype crash (Cisco
Controller) >transfer upload filename (Cisco
Controller) >transfer upload mode tftp (Cisco Controller) >transfer
This is the start of a display filter cross reference between Wireshark
and OmniPeek. The 1st installment is a table of advanced filters. More
filters will be added as time allows. It is a living doc, so check back
for changes every so often Please feel f...