- Preface
- Using the Command-Line Interface
- Using the Web Graphical User Interface
-
- Configuring the Switch for Access Point Discovery
- Configuring Data Encryption
- Configuring Retransmission Interval and Retry Count
- Configuring Adaptive Wireless Intrusion Prevention System
- Configuring Authentication for Access Points
- Converting Autonomous Access Points to Lightweight Mode
- Using Cisco Workgroup Bridges
- Configuring Probe Request Forwarding
- Optimizing RFID Tracking
- Configuring Country Codes
- Configuring Link Latency
- Configuring Power over Ethernet
-
- Preventing Unauthorized Access
- Controlling Switch Access with Passwords and Privilege Levels
- Configuring TACACS+
- Configuring RADIUS
- Configuring Kerberos
- Configuring Local Authentication and Authorization
- Configuring Secure Shell (SSH)
- Configuring Secure Socket Layer HTTP
- Configuring IPv4 ACLs
- Configuring IPv6 ACLs
- Configuring DHCP
- Configuring IP Source Guard
- Configuring Dynamic ARP Inspection
- Configuring IEEE 802.1x Port-Based Authentication
- Configuring MACsec Encryption
- Configuring Web-Based Authentication
- Configuring Port-Based Traffic Control
- Configuring IPv6 First Hop Security
- Configuring Cisco TrustSec
- Configuring Wireless Guest Access
- Managing Rogue Devices
- Classifying Rogue Access Points
- Configuring wIPS
- Configuring Intrusion Detection System
-
- Administering the System
- Performing Switch Setup Configuration
- Configuring Right-To-Use Licenses
- Configuring Administrator Usernames and Passwords
- Configuring 802.11 parameters and Band Selection
- Configuring Aggressive Load Balancing
- Configuring Client Roaming
- Configuring Application Visibility and Control
- Configuring Voice and Video Parameters
- Configuring RFID Tag Tracking
- Configuring Location Settings
- Monitoring Flow Control
- Configuring SDM Templates
- Configuring System Message Logs
- Configuring Online Diagnostics
- Managing Configuration Files
- Configuration Replace and Configuration Rollback
- Working with the Flash File System
- Working with Cisco IOS XE Software Bundles
- Troubleshooting the Software Configuration
Configuring Adaptive Wireless Intrusion Prevention System
Finding Feature Information
Your software release may not support all of the features documented in this module. For the latest feature information and caveats, see the release notes for your platform and software release.
Use Cisco Feature Navigator to find information about platform support and Cisco software image support. To access Cisco Feature Navigator, go to http://www.cisco.com/go/cfn. An account on Cisco.com is not required.
Prerequisites for Configuring wIPS
How to Configure wIPS on Access Points
Configuring wIPS on an Access Point (CLI)
1.
ap name Cisco_AP mode local
2.
ap name Cisco_AP dot11 5ghz shutdown
3.
ap name Cisco_AP dot11 24ghz shutdown
4.
ap name Cisco_AP mode monitor submode wips
5.
ap name Cisco_AP monitor-mode wips-optimized
6.
show ap dot11 24ghz monitor
7.
ap name Cisco_AP no dot11 5ghz shutdown
8.
ap name Cisco_AP no dot11 24ghz shutdown
DETAILED STEPS
Configuring wIPS on an Access Point (GUI)
| Step 1 | Choose
The All APs page is displayed. |
| Step 2 | Click the access
point name.
The AP > Edit page is displayed. |
| Step 3 | From the AP Mode drop-down list, choose one of the following options to configure the AP mode parameters: |
| Step 4 | From the AP Sub Mode drop-down list, choose WIPS. |
| Step 5 | Click Apply. |
| Step 6 | Click Save Configuration. |
Monitoring wIPS Information
![]() Note | The procedure to perform this task using the switch GUI is not currently available. |
1.
show ap name Cisco_AP config general
2.
show ap monitor-mode summary
3.
show wireless wps wips summary
4.
show wireless wps wips statistics
5.
clear wireless wips statistics
DETAILED STEPS
| Command or Action | Purpose | |
|---|---|---|
| Step 1 |
show ap name Cisco_AP config general Example: Switch# show ap name AP01 config general
|
Displays information on the wIPS submode on the access point. |
| Step 2 | show ap monitor-mode summary Example: Switch# show ap monitor-mode summary
| Displays the wIPS optimized channel scanning configuration on the access point. |
| Step 3 | show wireless wps wips summary Example: Switch# show wireless wps wips summary
| Displays the wIPS configuration forwarded by NCS or Prime to the switch. |
| Step 4 | show wireless wps wips statistics Example: Switch# show wireless wps wips statistics
| Displays the current state of wIPS operation on the switch. |
| Step 5 | clear wireless wips statistics Example: Switch# clear wireless wips statistics
| Clears the wIPS statistics on the switch. |
Configuration Examples for Configuring wIPS on Access Points
Displaying the Monitor Configuration Channel Set: Example
This example shows how to display the monitor configuration channel set:
Switch# show ap dot11 24ghz monitor
Default 802.11b AP monitoring
802.11b Monitor Mode........................... enable
802.11b Monitor Channels....................... Country channels
802.11b AP Coverage Interval................... 180 seconds
802.11b AP Load Interval....................... 60 seconds
802.11b AP Noise Interval...................... 180 seconds
802.11b AP Signal Strength Interval............ 60 seconds
Displaying wIPS Information: Examples
This example shows how to display information on the wIPS submode on the access point:
Switch# show ap name AP01 config general
Cisco AP Identifier.............. 3
Cisco AP Name.................... AP1131:46f2.98ac
...
AP Mode ......................... Monitor
Public Safety ................... Disabled Disabled
AP SubMode ...................... WIPS
This example shows how to display the wIPS optimized channel scanning configuration on the access point:
Switch# show ap monitor-mode summary
AP Name Ethernet MAC Status Scanning
Channel
List
------------- -------------- -------- ---------
AP1131:4f2.9a 00:16:4:f2:9:a WIPS 1,6,NA,NA
This example shows how to display the wIPS configuration forwarded by WCS to the switch:
Switch# show wireless wps wips summary
Policy Name.............. Default
Policy Version........... 3
This example shows how to display the current state of wIPS operation on the switch:
Switch# show wireless wps wips statistics
Policy Assignment Requests............ 1
Policy Assignment Responses........... 1
Policy Update Requests................ 0
Policy Update Responses............... 0
Policy Delete Requests................ 0
Policy Delete Responses............... 0
Alarm Updates......................... 13572
Device Updates........................ 8376
Device Update Requests................ 0
Device Update Responses............... 0
Forensic Updates...................... 1001
Invalid WIPS Payloads................. 0
Invalid Messages Received............. 0
CAPWAP Enqueue Failed................. 0
NMSP Enqueue Failed................... 0
NMSP Transmitted Packets.............. 22950
NMSP Transmit Packets Dropped......... 0
NMSP Largest Packet................... 1377

Feedback