5-73
Cisco Wireless LAN Controller Configuration Guide
OL-17037-01
Chapter 5 Configuring Security Solutions
Configuring Client Exclusion Policies
BSSID Radio Validator AP Last Source Addr Found Error Type Count Frame Types
----------------- ----- ------------- ------------------ ------ ------------ ----- -------
00:0b:85:56:c1:a0 a jatwo-1000b 00:01:02:03:04:05 Infra Invalid MIC 183 Assoc Req
Probe Req
Beacon
Infra Out of seq 4 Assoc Req
Infra Unexpected MIC 85 Reassoc Req
Client Decrypt err 1974 Reassoc Req
Disassoc
Client Replay err 74 Assoc Req
Probe Req
Beacon
Client Invalid ICV 174 Reassoc Req
Disassoc
Client Invalid header174 Assoc Req
Probe Req
Beacon
Client Brdcst disass 174 Reassoc Req
Disassoc
00:0b:85:56:c1:a0 b/g jatwo-1000b 00:01:02:03:04:05 Infra Out of seq 185 Reassoc Resp
Client Not encrypted 174 Assoc Resp
Probe Resp
Using the CLI to Debug MFP Issues
Use these commands if you experience any problems with MFP:
•
debug wps mfp
?
{
enable
|
disable
}
where
?
is one of the following:
client
—Configures debugging for client MFP messages.
capwap
—Configures debugging for MFP messages between the controller and access points.
detail
—Configures detailed debugging for MFP messages.
report
—Configures debugging for MFP reporting.
mm
—Configures debugging for MFP mobility (inter-controller) messages.
Configuring Client Exclusion Policies
Follow these steps to configure the controller to exclude clients under certain conditions using the
controller GUI.
Step 1
Click
Security
>
Wireless Protection Policies
>
Client Exclusion Policies
to open the Client Exclusion
Policies page.
Step 2
Check any of these check boxes if you want the controller to exclude clients for the condition specified.
The default value for each exclusion policy is enabled.
•
Excessive 802.11 Association Failures
—Clients are excluded on the sixth 802.11 association
attempt, after five consecutive failures.
•
Excessive 802.11 Authentication Failures
—Clients are excluded on the sixth 802.11
authentication attempt, after five consecutive failures.
•
Excessive 802.1X Authentication Failures
—Clients are excluded on the fourth 802.1X
authentication attempt, after three consecutive failures.