All MIBs › AIRESPACE-WIRELESS-MIB › bsnSignatureAttackDetected
bsnSignatureAttackDetected
Module: AIRESPACE-WIRELESS-MIB
OID (symbolic): AIRESPACE-WIRELESS-MIB::bsnSignatureAttackDetected
OID (numeric): 1.3.6.1.4.1.14179.2.6.3.70
Node type: NOTIFICATION-TYPE
Description: This trap is sent out when a signature attack is detected by the switch. The standard and custom signatures are predefined on the switch (see bsnSignatureConfig group). The signatures also defines if its detection should be reported. The trap variables bsnSignatureName and bsnSignatureDescription are retrieved from the detected signature definition. Clear Trap Variable is turned on when the signature attack stops. The signature's quiet time configuration speicifes the time after which the clear trap would be sent. bsnSignatureMacInfo indicates whether the signature is used to track pattern matches for all source MAC addresses together or seperately for individual source MAC addresses. bsnSignatureAttackFrequency will carry the value for a specific MAC address or for all MAC addresses depending on bsnSignatureMacInfo.
Examples
Send this trap to an SNMP manager — replace <manager> with the IP or hostname of your monitoring server (SNMPv2c):
snmptrap -v2c -c public <manager> '' AIRESPACE-WIRELESS-MIB::bsnSignatureAttackDetected snmptrap -v2c -c public <manager> '' 1.3.6.1.4.1.14179.2.6.3.70
Listen for incoming traps on the manager host (-f keeps it in the foreground, -Lo prints to stdout — useful for testing):
snmptrapd -f -Lo -c /dev/null authCommunity log public
Example snmptrapd log entry:
zoo11-linux.zoo [UDP: [192.168.30.111]:60980->[192.168.30.10]:162]: DISMAN-EVENT-MIB::sysUpTimeInstance = Timeticks: (262929460) 30 days, 10:21:34.60 SNMPv2-MIB::snmpTrapOID.0 = OID: AIRESPACE-WIRELESS-MIB::bsnSignatureAttackDetected
SNMPv3 example:
snmptrap -v3 -l authPriv -u snmpv3user -a SHA -A "AuthPass1" -x AES -X "PrivPass1" <manager> '' AIRESPACE-WIRELESS-MIB::bsnSignatureAttackDetected
Start monitoring Cisco (Airespace) Wireless LAN Controllers (legacy) with a free 30-day trial of IPNetwork Monitor. Create custom SNMP monitor using the AIRESPACE-WIRELESS-MIB::bsnSignatureAttackDetected OID value, configure state conditions and alerts, and monitor any Cisco (Airespace) Wireless LAN Controllers (legacy) from a single console.
OID Breakdown
Upper-level ancestors (7 from the standard OID tree / other modules)
| Numeric OID | Name | Module |
|---|---|---|
| 1 | iso | LANART-AGENT |
| 1.3 | org | AirPair-MIB |
| 1.3.6 | dod | AirPair-MIB |
| 1.3.6.1 | internet | AirPair-MIB |
| 1.3.6.1.4 | private | AirPair-MIB |
| 1.3.6.1.4.1 | enterprises | AirPair-MIB |
| 1.3.6.1.4.1.14179 | airespace | AIRESPACE-REF-MIB |
| Numeric OID | Name | Module |
|---|---|---|
| 1.3.6.1.4.1.14179.2 | bsnWireless | AIRESPACE-WIRELESS-MIB |
| 1.3.6.1.4.1.14179.2.6 | bsnTrap | AIRESPACE-WIRELESS-MIB |
| 1.3.6.1.4.1.14179.2.6.3 | bsnTraps | AIRESPACE-WIRELESS-MIB |
| 1.3.6.1.4.1.14179.2.6.3.70 | bsnSignatureAttackDetected | AIRESPACE-WIRELESS-MIB |