WLAN/4/WIDS_DETECT_FLOOD_ATTACK:OID [oid] Detected attack. (Monitor APMAC=[OPAQUE], Device Mac=[OPAQUE], Device channel=[INTEGER], Attack type=[INTEGER], Attack type string=[OCTET])
A flood attack was detected.
| Alarm ID | Alarm Severity | Alarm Type |
|---|---|---|
| 1.3.6.1.4.1.2011.6.139.15.1.1.5 | Warning | environmentalAlarm(6) |
| Name | Meaning |
|---|---|
| oid | Indicates the OID of the alarm. |
Monitor APMAC |
Indicates the MAC address of a monitoring AP. |
| Device Mac | Indicates the MAC address of the attacking device. |
| Device channel | Indicates the channel of the attacking device. |
| Attack type | Indicates the ID of attack type.
|
| Attack type string | Indicates the character string describing the attacking device type. |
The device is busy processing flood attack packets, which occupies too many CPU resources.
Enter the WIDS profile view and run the flood-detect interval and flood-detect threshold commands to configure the flood attack detection period and the maximum number of packets of the same type that an AP can receive within the period.