UNEXPECTED_CHANNEL_BEACON with Ubiquiti access points #346
Unanswered
andrewbeard
asked this question in
Questions
Replies: 3 comments 9 replies
-
Interesting! Can you share the alert details with me? I'm interested in the "Meta Information" fields on the right hand side on the alert page. |
Beta Was this translation helpful? Give feedback.
1 reply
-
I am experience the same situation with Sophos Access Points. |
Beta Was this translation helpful? Give feedback.
6 replies
-
If you add all the channels to expected when would the alert ever fire, bad
actor or not?
On Thu, May 13, 2021 at 8:08 PM Brandon Taylor ***@***.***> wrote:
I would add those expected channels instead. Remember the point is really
to see unexpected events. If you exclude the check entirely, you'll do just
that. I think your better off knowing if a bad actor slips then not at all
:).
—
You are receiving this because you authored the thread.
Reply to this email directly, view it on GitHub
<#346 (reply in thread)>,
or unsubscribe
<https://github.com/notifications/unsubscribe-auth/ADYYHYZVJ2IEU37CNGPVC6DTNRSYNANCNFSM4ZZYMKXA>
.
--
Andrew Beard
***@***.***
|
Beta Was this translation helpful? Give feedback.
2 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
I have 3 dual-band UniFi access points set up in my environment all on one SSID, with each locked to specific channels to avoid overlaps. I set up my config to monitor all channels 2.4 Ghz along with the 3 5 Ghz channels in use, but with my network restricted to the 6 in use. Unfortunately this has resulted in a ton of UNEXPECTED_CHANNEL_BEACON alerts, on literally every 2.4 Ghz channel from 1-11. On some channels (like 2 and 10) the alerts are relatively far between, with only a frame picked up every hour or so. In each case I can see the vast majority of frames on the expected channel, and the number of frames decreasing rapidly the further it gets away from expected (for example, 6 is in use and see a lot of traffic. 7 sees less than 1/10th of that, and 8 sees less than 1/100th).
For the moment I've disabled the unexpected_channel alert types, but I'm trying to figure out what's going on. Is it normal for some AP manufacturers to beacon on alternate channels despite being configured to use a specific channel? I was thinking maybe because of the adjacent behavior it could have something to do with using a wide channel width, but after reviewing my config all my 2.4 Ghz channels are 20 Mhz wide.
Beta Was this translation helpful? Give feedback.
All reactions