Cisco Catalyst Center Rogue Management and aWIPS Application Quick Start Guide, Release 3.1.x

PDF

About aWIPS profiles

Want to summarize with AI?

Log in

Overview

If the rogue AP is attached to non-ACCESS mode interfaces, the network admin must contain the interface either manually or through a CLI command.

Configure aWIPS profiles to select required signatures, set thresholds for detecting denial of service (DoS) attacks, and enable forensic capture at the signature level. Adjust thresholds to control the number of alarms generated for each aWIPS signature during a specific time period.

This table lists the supported devices for aWIPS profile configuration for various versions of Catalyst Center:

Table 1. Supported devices for aWIPS profile configuration

Supported devices

IOS-XE version

Catalyst Center version

  • Cisco Catalyst 9800 Series Wireless Controller

  • Cisco Catalyst 9800-CL Cloud Wireless Controller

  • Cisco Embedded Wireless Controller on Catalyst Access Points

  • Cisco Catalyst 9800 Embedded Wireless Controller for Catalyst 9300 Series Switches

  • Cisco Catalyst 9400 Series Switches

  • Cisco Catalyst 9500 Series Switches

17.4 to 17.13

2.3.7.4

17.4 to 17.14

2.3.7.5

17.4 to 17.15

2.3.7.6

17.4 to 17.15

2.3.7.7

Note

For SD-Access use cases, for aWIPS profiles to work, you must enable the wireless module on Cisco Catalyst 9300 Series Switches, Cisco Catalyst 9400 Series Switches, and Cisco Catalyst 9500 Series Switches.


Prerequisites for aWIPS profile

  • Verify the network connectivity between the Cisco Wireless Controller and Catalyst Center.

  • Make sure that the network device is reachable from Catalyst Center and has downloaded the aWIPS profile configuration from Catalyst Center.

    Note

    To avoid aWIPS profile download failures in a Fabric in a Box SD-Access setup, ensure that the Infrastructure Virtual Network (Infra_VN) uses a routable IP subnet in the global routing table.

  • To enable forensic capture, complete these tasks:

    • Ensure there is network connectivity between APs and Catalyst Center.

    • Establish the Google Remote Procedure Call (gRPC) tunnel interface between APs and Catalyst Center. Use the show ap icap connection command to confirm that the status is READY.

    • Open the required ports between Catalyst Center and links to the network devices.

    • Configure an NTP server on the AP to prevent time lag between Catalyst Center and APs. For information, see the Cisco Catalyst 9800 Series Wireless Controller Software Configuration Guide, Cisco IOS XE Dublin 17.12.x.