Wireless Access

last person joined: 14 hours ago 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Configuring WIP to send SNMP traps

This thread has been viewed 7 times
  • 1.  Configuring WIP to send SNMP traps

    Posted Nov 08, 2012 10:25 AM

    All, can anyone point me in the direction of finding out how to configure wip so that if a rogue AP appears on the network with the same SSID as a valid one that it send out a trap?



  • 2.  RE: Configuring WIP to send SNMP traps

    EMPLOYEE
    Posted Nov 08, 2012 10:49 AM

    You need:

     

    1.  The RFProtect License

    2.  Configure Detection of AP Impersonation (below)

    3.  Configure a Trap Destination in Configuration> SNMP.

    The trap for this is automatically sent to the Trap Destination

     

     

    wip.png



  • 3.  RE: Configuring WIP to send SNMP traps

    Posted Nov 08, 2012 10:57 AM

    Thanks I will give that a go.



  • 4.  RE: Configuring WIP to send SNMP traps

    Posted Nov 09, 2012 07:29 AM

    Well as soon as i put in my trap received my mangament system became completely flooded from the wifi controller. Cant see  what the alerts are for , they look non descritpt.  How can i stop the controller from sending anythig BUT the roge ap with duplicat SSID alerts?



  • 5.  RE: Configuring WIP to send SNMP traps

    Posted Nov 09, 2012 08:58 AM

    Colin,

     

     

    I see that you can do the command to look at all the traps that are sent which are a lot. and then you can use:-

     (config) #snmp-server trap disable wlsxWirelessBridge
    (config) #snmp-server trap disable coldStart

     

    But if I only want the trap for a rogue ap with same SSID as a legitimate one sent which is this one? Also, do I have to do a disable for the hundred or so traps one by one?

     

     

    Cheers!



  • 6.  RE: Configuring WIP to send SNMP traps

    EMPLOYEE
    Posted Nov 09, 2012 09:11 AM
      |   view attached

    Attached is a list that someone on our organization put together.  Those are the raw commands to enable/disable traps.  If you search and replace enable with disable, you will disable all the traps.  Paste that in.

     

    You can then enable only the traps that you want.

     

    Attachment(s)

    txt
    SNMP trap commands.txt   11 KB 1 version


  • 7.  RE: Configuring WIP to send SNMP traps

    Posted Nov 09, 2012 10:05 AM

    Thanks Colin but do you know which is the right trap for the fake AP with the same SSID one?



  • 8.  RE: Configuring WIP to send SNMP traps

    Posted Nov 09, 2012 10:17 AM

    I think the one you want is "wlsxAPImpersonation".



  • 9.  RE: Configuring WIP to send SNMP traps

    Posted Nov 09, 2012 10:19 AM

    Thanks!

     

    Just to clarify - doing a 'no' on all those traps will not affectig normal reporting of wip to the dashboard will it? This will only affect what is sent to a third party network?



  • 10.  RE: Configuring WIP to send SNMP traps

    Posted Nov 09, 2012 10:24 AM

    Thats right.  Doing a "no" on the enabled traps will only affect what the configured trap receivers see, not the dashboard on the controller.



  • 11.  RE: Configuring WIP to send SNMP traps

    Posted Nov 09, 2012 10:26 AM

    Thanks:)

     

    Do you think that on the trap receiver, that you have to create a mib to see these traps or do you just have to tell it the read string and it will receive the traps legibly?



  • 12.  RE: Configuring WIP to send SNMP traps

    Posted Nov 09, 2012 10:30 AM

    Also do the traps have to removed from all controllers or just master?



  • 13.  RE: Configuring WIP to send SNMP traps

    Posted Nov 09, 2012 10:33 AM

    All controllers, AFAIK.  I dont think the master sync's the SNMP config to the locals.



  • 14.  RE: Configuring WIP to send SNMP traps

    Posted Nov 09, 2012 10:35 AM

    Thanks! Looks like  need the MIB and I have to add to all my controllers..



  • 15.  RE: Configuring WIP to send SNMP traps

    Posted Nov 09, 2012 11:51 AM

    Struggling to find the MIB on the support site - can someone paste me the link please?



  • 16.  RE: Configuring WIP to send SNMP traps

    Posted Nov 09, 2012 12:06 PM

    On the support site under:

     

    Downloads > ArubaOS > General Availability > Current Releases > Release 6.1.x > Release 6.1.3.5

     

    File is named standard-mibs....

     

    It is always in the same folder as the code.



  • 17.  RE: Configuring WIP to send SNMP traps

    Posted Nov 09, 2012 10:23 AM

    And possibly "wlsxValidSSIDViolation"



  • 18.  RE: Configuring WIP to send SNMP traps

    Posted Nov 12, 2012 04:02 AM

    I tried doing the same.

    I am configuring Solarwinds to monitor the controller for WIPS.

    However when I add the OID for wlsxAPImpersonation, it says the OID is not supported. 

    Any thoughts?



  • 19.  RE: Configuring WIP to send SNMP traps

    Posted Nov 12, 2012 05:38 AM

    I downloaded the tar and expanded and it gives about 15 .my files. Is this correct? Do i have to import these one by into my management station?



  • 20.  RE: Configuring WIP to send SNMP traps

    Posted Nov 12, 2012 06:47 AM

    On the support site under:

     

    Downloads > ArubaOS > General Availability > Current Releases > Release 6.1.x > Release 6.1.3.5

     

    File is named standard-mibs....

     

    It is always in the same folder as the code.

     

     

    Is this definitaly the standard-mibs file or is it the 'aruba-mibs' one?

    I am finding it difficult importing these into my NMS....



  • 21.  RE: Configuring WIP to send SNMP traps

    Posted Nov 12, 2012 11:17 AM

    Ok i added the aruba mib file and my managment systems seems to have taken it, Immediately after configuring my management station as a snmp trap agent it srarted receiving countless traps.  I disabled all traps and enabled just the two mentioned in which to alert for duplicate SSID and my management station doesnt receive the trap.. I had created a wireless hotspot on a android phone and entered a SSID with the same name as a bona fide one. I can even see this phone advertising on the aruba dashboard with the bogus SSID but the trap isnt sent.... any ideas ?



  • 22.  RE: Configuring WIP to send SNMP traps

    EMPLOYEE
    Posted Nov 12, 2012 12:52 PM

    By default that configuration to detect a duplicate SSID is not on.  Do you have detection enabled in the IDS profile?

     



  • 23.  RE: Configuring WIP to send SNMP traps

    Posted Nov 12, 2012 01:38 PM

    I just did what was suggested in this thread. Are toae two trap profiles incorrect? If so how do you switch on what you suggest?



  • 24.  RE: Configuring WIP to send SNMP traps

    EMPLOYEE
    Posted Nov 12, 2012 01:42 PM

    The traps will only be sent if:

     

    A third-party access point has the same wireless mac address as one of your own 

    A third-party access point has the same wireless mac address AND SSID as one of your own.

     

    Just having the same SSID will not activate the impersonation trap.

     



  • 25.  RE: Configuring WIP to send SNMP traps

    Posted Nov 12, 2012 02:15 PM

    So what do you switch on to enable a trap if someone puts a ap on the network with the same ssid please?



  • 26.  RE: Configuring WIP to send SNMP traps

    EMPLOYEE
    Posted Nov 12, 2012 08:26 PM

    There are two things that you need to do:

     

    1.  Use the WIP Wizard and configure a policy that detects Valid SSID misuse in your "Default" ap group.

     

    wip.png

     

    2.  Look for the wlsxValidSSIDViolation trap.

     

    Alternatively, you can just enable the "Detect Valid SSID Misuse" in the IDS Unauthorized Profile in that AP Group.



  • 27.  RE: Configuring WIP to send SNMP traps

    Posted Nov 13, 2012 08:56 AM

    Thanks,

     

    I have added in WIP wizard and ensured that wlsxValidSSIDViolation is enabled in the trap list for the same ap group that I set upin  the default wip wizard. I switched on the android device with the same SSID and I didnt get anythimg. Would i see this in the 'show snmp trap-queue' command if it had been generated?



  • 28.  RE: Configuring WIP to send SNMP traps

    Posted Nov 13, 2012 09:09 AM

    To add to my last post, I went back into the default wip wizard and when you select the default wizard in the letft window it doesnt say that the Ap groups I added the last time are there. I tried a few times and saw that in the summary just before you push the policy it definitaly has the ap groups I slected there but again if I go back in it shows as nothing is in there. Is this normal behaviour?



  • 29.  RE: Configuring WIP to send SNMP traps

    EMPLOYEE
    Posted Nov 15, 2012 01:21 AM

    If you are using an access point, it will take time to scan the channel of the duplicate AP.  If you are using an Air Monitor, however, it will take much less time to scan, identify and report on the duplicate device.

     



  • 30.  RE: Configuring WIP to send SNMP traps

    Posted Nov 09, 2012 10:30 AM

    If Airwave is the trap receiver, it has the MIB loaded already.  If Airwave is not, you will have to get the MIB from Aruba's support site.  Without the MIB, the trap will be received legibly, but the codes and OIDs may not make sense.  BTW - there is a MIB guide on the Aruba support site that describes each of these traps (even though the AP impersonation still says "Detects Station impersonation").