Mitigating WiFi deauth attacks with Ubiquiti Protected Management Frames (2022)
blog.steveendow.com
blog.steveendow.com
Edit: also, from my notes at setup time, some devices could connect but then had trouble roaming.
That might sound fine at first glance, so here’s a common scenario we’d have:
During a renovation on a high-rise building BigCorp that still occupies office space on that floor, is happily (unknowingly/uncaringly) spamming deauths and even spoofing our BSSID and to our field techs it would generally just look like “incorrect password”
I wrote a long internal bulletin about it, mostly geared towards helping our techs identifying the issue (with varying levels of networking knowledge) and getting to someone in IT to help.
This is the easy wire shark proof if you suspect it:
#filter for deauthentication frames `(wlan.fc.type == 0)&&(wlan.fc.type_subtype == 0x0c)` Especially looking for a reason code of 2 `Previous authentication no longer valid.`