Rogue Detection and Countermeasures 565

Displaying SSID or BSSID Information for a Mobility Domain

To display SSID or BSSID information for an entire Mobility Domain, use the following command on the seed switch:

show rfdetect mobility-domain [ssid ssid-namebssid mac-addr]

The following command displays summary information for all SSIDs and BSSIDs detected in the Mobility Domain:

23x0# show rfdetect mobility-domain

Total number of entries: 194

 

 

 

 

Flags: i = infrastructure, a =

ad-hoc,

u = unresolved

c = CCMP, t = TKIP, 1 =

104-bit

WEP,

4 = 40-bit WEP, w = WEP(non-WPA)

BSSID

Vendor

Type

Flags

SSID

-----------------

------------

-----

------

--------------------------------

00:07:50:d5:cc:91

Cisco

intfr

i----

w

r27-cisco1200-2

00:07:50:d5:dc:78

Cisco

intfr

i----

w

r116-cisco1200-2

00:09:b7:7b:8a:54

Cisco

intfr

i-----

 

00:0a:5e:4b:4a:c0

3Com

intfr

i-----

public

00:0a:5e:4b:4a:c2

3Com

intfr

i----

w

nortelwlan

00:0a:5e:4b:4a:c4

3Com

intfr

ic

----

nrtl-ccmp

00:0a:5e:4b:4a:c6

3Com

intfr

i----

w

nrtl-tkip

00:0a:5e:4b:4a:c8

3Com

intfr

i----

w

nrtl-voip

00:0a:5e:4b:4a:ca

3Com

intfr i-----

nrtl-webaaa

...

 

 

 

 

 

The lines in this display are compiled from data from multiple listeners (AP radios). If an item has the value unresolved, not all listeners agree on the value for that item. Generally, an unresolved state occurs only when an AP or a Mobility Domain is still coming up, and lasts only briefly.

The following command displays detailed information for rogues using SSID nrtl-webaaa.

23x0# show rfdetect mobility-domain ssid nrtl-webaaa

BSSID: 00:0a:5e:4b:4a:ca Vendor: 3Com SSID:nrtl-webaaa

Type: intfr Adhoc: no Crypto-types: clear

WSS-IPaddress:10.8.121.102Port/Radio/Ch:3/1/11Mac:00:0b:0e:00:0a:6a Device-type: interfering Adhoc: no Crypto-types: clear

RSSI: -85 SSID: nrtl-webaaa

BSSID: 00:0b:0e:00:7a:8a Vendor: Nortel SSID: nrtl-webaaa

Type: intfr Adhoc: no Crypto-types: clear

WSS-IPaddress:10.8.121.102Port/Radio/Ch:3/1/1Mac:00:0b:0e:00:0a:6a Device-type: interfering Adhoc: no Crypto-types: clear

RSSI: -75 SSID: nrtl-webaaa

WSS-IPaddress:10.3.8.103Port/Radio/Ch:dap1/1/1Mac:00:0b:0e:76:56:82 Device-type: interfering Adhoc: no Crypto-types: clear

RSSI: -76 SSID: nrtl-webaaa

Two types of information are shown. The lines that are not indented show the BSSID, vendor, and information about the SSID. The indented lines that follow this information indicate the listeners (AP radios) that detected the SSID. Each set of indented lines is for a separate AP listener.

Nortel WLAN Security Switch 2300 Series Configuration Guide

Page 565
Image 565
Nortel Networks 2300 manual Displaying Ssid or Bssid Information for a Mobility Domain, 23x0# show rfdetect mobility-domain