<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Possible DoS attack in M and MSM Series</title>
    <link>https://community.hpe.com/t5/m-and-msm-series/possible-dos-attack/m-p/5905919#M1664</link>
    <description>After reboot the messages has been desappeared. :)</description>
    <pubDate>Thu, 20 Dec 2012 16:59:15 GMT</pubDate>
    <dc:creator>david-rivas</dc:creator>
    <dc:date>2012-12-20T16:59:15Z</dc:date>
    <item>
      <title>Possible DoS attack</title>
      <link>https://community.hpe.com/t5/m-and-msm-series/possible-dos-attack/m-p/5905593#M1657</link>
      <description>&lt;P&gt;Hello, I am having problems with user authentication. The configuration has been running for a months with no problems but since three days ago, I am having problems with authentication, I have to authenticate several times before get login. I have seen some strange logs in the controller, 4 MAC address that are continuously requesting Radius authentication, exceeding the maximum request queued on the controller.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Dec 20 10:25:30 warning iprulesmgr Discarding RADIUS Request (id='25') from RADIUS Client (ip-address='169.254.0.12',port='32772') as the maximum simultaneous number of RADIUS Requests waiting for answer have been reached (2900).&lt;/P&gt;&lt;P&gt;Dec 20 10:25:30 warning iprulesmgr Discarding RADIUS Request (id='130') from RADIUS Client (ip-address='169.254.0.12',port='32772') as the maximum simultaneous number of RADIUS Requests waiting for answer have been reached (2900).&lt;/P&gt;&lt;P&gt;Dec 20 10:25:30 warning iprulesmgr Discarding RADIUS Request (id='162') from RADIUS Client (ip-address='169.254.0.12',port='32772') as the maximum simultaneous number of RADIUS Requests waiting for answer have been reached (2900).&lt;/P&gt;&lt;P&gt;Dec 20 10:25:30 debug iprulesmgr Received RADIUS Accounting Request (id='102',acct-status-type='2') for user (calling-station-id='64:A7:69:84:3B:67',virtual-ap-index='4') from RADIUS Client (ip-address='169.254.0.12',port='32772',called-station-id='00:24:A8:B0:1B:40').&lt;/P&gt;&lt;P&gt;Dec 20 10:25:30 debug iprulesmgr Received RADIUS Accounting Request (id='35',acct-status-type='2') for user (calling-station-id='64:A7:69:84:3B:67',virtual-ap-index='4') from RADIUS Client (ip-address='169.254.0.12',port='32772',called-station-id='00:24:A8:B0:1B:40').&lt;/P&gt;&lt;P&gt;Dec 20 10:25:30 debug iprulesmgr Received RADIUS Accounting Request (id='208',acct-status-type='2') for user (calling-station-id='64:A7:69:84:3B:67',virtual-ap-index='4') from RADIUS Client (ip-address='169.254.0.12',port='32772',called-station-id='00:24:A8:B0:1B:40').&lt;/P&gt;&lt;P&gt;Dec 20 10:25:30 debug iprulesmgr Received RADIUS Accounting Request (id='253',acct-status-type='2') for user (calling-station-id='50:CC:F8:57:90:C7',virtual-ap-index='4') from RADIUS Client (ip-address='169.254.0.12',port='32772',called-station-id='00:24:A8:B0:1B:40').&lt;/P&gt;&lt;P&gt;Dec 20 10:25:30 debug iprulesmgr Received RADIUS Accounting Request (id='229',acct-status-type='2') for user (calling-station-id='64:A7:69:84:3B:67',virtual-ap-index='4') from RADIUS Client (ip-address='169.254.0.12',port='32772',called-station-id='00:24:A8:B0:1B:40').&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried to block this devices with MAC filter, device wireless association is blocked, but Radius authentication are not. The called-station-id is not an AP of my controller&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any idea?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Thu, 20 Dec 2012 11:06:11 GMT</pubDate>
      <guid>https://community.hpe.com/t5/m-and-msm-series/possible-dos-attack/m-p/5905593#M1657</guid>
      <dc:creator>david-rivas</dc:creator>
      <dc:date>2012-12-20T11:06:11Z</dc:date>
    </item>
    <item>
      <title>Re: Possible DoS attack</title>
      <link>https://community.hpe.com/t5/m-and-msm-series/possible-dos-attack/m-p/5905785#M1660</link>
      <description>&lt;P&gt;this is not DoS attack&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;check client certificate and ssid profile&amp;nbsp;&lt;/P&gt;&lt;P&gt;some wireless client can't authentication&amp;nbsp; and can't get ip address on your system (169.254 address is apipa address)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if you see more than mac address&amp;nbsp; create new eap certificate on radius server for authentication&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Dec 2012 14:52:01 GMT</pubDate>
      <guid>https://community.hpe.com/t5/m-and-msm-series/possible-dos-attack/m-p/5905785#M1660</guid>
      <dc:creator>cenk sasmaztin</dc:creator>
      <dc:date>2012-12-20T14:52:01Z</dc:date>
    </item>
    <item>
      <title>Re: Possible DoS attack</title>
      <link>https://community.hpe.com/t5/m-and-msm-series/possible-dos-attack/m-p/5905891#M1662</link>
      <description>&lt;P&gt;Hello Cenk,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think the IP pipa belongs to the AP that has received the request form the user... also the MAC address of the AP does not correspond to any AP configured on the controller. Even the MAC address is not located on the LAN (I used show mac-address ... on the Core switch and it does not exists)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is no acces problem. Most of the users are connected, but they have packet loses. Other users require to authenticate several times to have access. I have only one Radius server and I have not seen errors on the event viwer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have found the four devices that are sending Radius requests. We have turn wifi off, but request still present.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will reboot the Controller.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Dec 2012 16:16:18 GMT</pubDate>
      <guid>https://community.hpe.com/t5/m-and-msm-series/possible-dos-attack/m-p/5905891#M1662</guid>
      <dc:creator>david-rivas</dc:creator>
      <dc:date>2012-12-20T16:16:18Z</dc:date>
    </item>
    <item>
      <title>Re: Possible DoS attack</title>
      <link>https://community.hpe.com/t5/m-and-msm-series/possible-dos-attack/m-p/5905919#M1664</link>
      <description>After reboot the messages has been desappeared. :)</description>
      <pubDate>Thu, 20 Dec 2012 16:59:15 GMT</pubDate>
      <guid>https://community.hpe.com/t5/m-and-msm-series/possible-dos-attack/m-p/5905919#M1664</guid>
      <dc:creator>david-rivas</dc:creator>
      <dc:date>2012-12-20T16:59:15Z</dc:date>
    </item>
  </channel>
</rss>

