5-38
Cisco Wireless LAN Controller Configuration Guide
OL-9141-03
Chapter 5 Configuring Security Solutions
Configuring IDS
Using the CLI to View IDS Signature Events
Use these commands to view signature events using the controller CLI.
1.
To see all of the standard and custom signatures installed on the controller, enter this command:
show wps signature summary
2.
To see the number of attacks detected by the enabled signatures, enter this command:
show wps signature events summary
Information similar to the following appears:
Precedence Signature Name Type
No. Events
---------- ------------------ ----- -----------
1
Bcast deauth
Standard
2
2
NULL probe resp 1 Standard 1
3.
To see more information on the attacks detected by a particular standard or custom signature, enter
this command:
show wps signature events
{
standard
|
custom
}
precedence#
summary
Information similar to the following appears:
Precedence....................................... 1
Signature Name................................... Bcast deauth
Type............................................. Standard
Number of active events....................... 2
Source MAC Addr Track Method Frequency No. APs Last Heard
----------------- ------------ --------- -------- ------------------------
00:01:02:03:04:01 Per Signature 4
3
Tue Dec 6 00:17:44 2005
00:01:02:03:04:01 Per Mac 6
2
Tue Dec 6 00:30:04 2005
4.
To see information on attacks that are tracked by access points on a per-signature and per-channel
basis, enter this command:
show wps signature events
{
standard
|
custom
}
precedence#
detailed per-signature
source_mac
5.
To see information on attacks that are tracked by access points on an individual-client basis (by
MAC address), enter this command:
show wps signature events
{
standard
|
custom
}
precedence#
detailed per-mac
source_mac
Information similar to the following appears:
Source MAC....................................... 00:01:02:03:04:01
Precedence....................................... 1
Signature Name................................... Bcast deauth
Type............................................. Standard
Track............................................ Per Mac
Frequency........................................ 6
Reported By
AP 1
MAC Address.............................. 00:0b:85:01:4d:80
Name..................................... Test_AP_1
Radio Type............................... 802.11bg
Channel.................................. 4
Last reported by this AP................. Tue Dec 6 00:17:49 2005