5-107
Cisco Wireless LAN Controller Configuration Guide
OL-17037-01
Chapter 5 Configuring Security Solutions
Configuring IDS
Using the CLI to View Shunned Clients
Follow these steps to view the list of clients that the IDS sensors have identified to be shunned using the
controller CLI.
Step 1
To view the list of clients to be shunned, enter this command:
show wps shun-list
Step 2
To force the controller to sync up with other controllers in the mobility group for the shun list, enter this
command:
config wps shun-list re-sync
Configuring IDS Signatures
You can configure IDS signatures, or bit-pattern matching rules used to identify various types of attacks
in incoming 802.11 packets, on the controller. When the signatures are enabled, the access points joined
to the controller perform signature analysis on the received 802.11 data or management frames and
report any discrepancies to the controller. If an attack is detected, appropriate mitigation is initiated.
Cisco supports 17 standard signatures on the controller as shown on the Standard Signatures page (see
Figure 5-56
Standard Signatures Page