Network Management

last person joined: 15 hours ago 

Keep an informative eye on your network with HPE Aruba Networking network management solutions
Expand all | Collapse all

Airwave keeps logging messages for attacks/vulnerabilities not checked in IDS profile

This thread has been viewed 0 times
  • 1.  Airwave keeps logging messages for attacks/vulnerabilities not checked in IDS profile

    Posted Jan 07, 2014 08:52 PM

    We are getting hundreds of the "Invalid MAC OUI" events logged in RAPIDS even though the ArubaOS IDS profile doesn't have that particular option checked.

     

    I've tried checking it and updating, and then unchecking it and updating again to see if that resolves the issue but this is annoying beyond belief.  I've had to temporarily suspend email from Airwave on alerts because there were so many my inbox was sounding like the door chime on the door to a quarter priced starbucks....

     

    Any suggestions?  Otherwise I'll open a support case...



  • 2.  RE: Airwave keeps logging messages for attacks/vulnerabilities not checked in IDS profile

    EMPLOYEE
    Posted Jan 08, 2014 04:55 AM

    @eickst wrote:

    We are getting hundreds of the "Invalid MAC OUI" events logged in RAPIDS even though the ArubaOS IDS profile doesn't have that particular option checked.

     

    I've tried checking it and updating, and then unchecking it and updating again to see if that resolves the issue but this is annoying beyond belief.  I've had to temporarily suspend email from Airwave on alerts because there were so many my inbox was sounding like the door chime on the door to a quarter priced starbucks....

     

    Any suggestions?  Otherwise I'll open a support case...


    Well, it is coming from somewhere.  Type "show snmp trap-queue" on the commandline of the controller to see if the controller is indeed sending those traps.  You might have the wrong IDS profile configured.  



  • 3.  RE: Airwave keeps logging messages for attacks/vulnerabilities not checked in IDS profile

    Posted Jan 09, 2014 01:55 PM

    Only have one IDS profile.  Trap queue didn't show them but I went ahead and disabled the trap in the snmp config of each controller.  We'll see if that kills it.