AP Spoof Event Log Details

SOLVED
amy27601
Conversationalist

AP Spoof Event Log Details

Hello,

I'm troubleshooting AP Spoof Air Marshal alerts that periodically show up. Could someone help me read the details of the alert? Is the dst MAC the MAC address of the device that is spoofing the SSID? The bssid and src mac addresses are the AP that logged the event.

 

vap: 1, bssid: 0A:8D:CB:70:38:A0, src: 0A:8D:CB:70:38:A0  « hide 

dstC2:3F:9B:AC:BD:BC
radio1
band5
channel40
rssi35
fc_type0
fc_subtype13
1 ACCEPTED SOLUTION
Inderdeep
Kind of a big deal
Kind of a big deal

@amy27601 : Check Air Marshal Containment below 

https://documentation.meraki.com/MR/Monitoring_and_Reporting/Air_Marshal 

Regards/Inder
Cisco IT Blogs awarded in 2020 & 2021
www.thenetworkdna.com

View solution in original post

2 REPLIES 2
Inderdeep
Kind of a big deal
Kind of a big deal

@amy27601 : Check Air Marshal Containment below 

https://documentation.meraki.com/MR/Monitoring_and_Reporting/Air_Marshal 

Regards/Inder
Cisco IT Blogs awarded in 2020 & 2021
www.thenetworkdna.com
amy27601
Conversationalist

Thank you @Inderdeep 

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels