<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IdentiFi Wireless Controller f/w 8.21.06.0006 reporting High CPU Utilization for HTTPD Process in FAQs</title>
    <link>https://community.extremenetworks.com/t5/faqs/identifi-wireless-controller-f-w-8-21-06-0006-reporting-high-cpu/m-p/46466#M397</link>
    <description>Article ID: 15085 &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Products&lt;/B&gt;&lt;BR /&gt;
C20, C25, C4110, C5110, C5210, V2110; firmware 8.11.01.0161 through 8.21.06.0006&lt;BR /&gt;
IdentiFi (formerly Enterasys, HiPath) Wireless Controller &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Symptoms&lt;/B&gt;&lt;BR /&gt;
Users are unable to connect to the Wireless network.&lt;BR /&gt;
  -and/or-&lt;BR /&gt;
Overall client performance issues, such as poor connections, dropped connections, or spotty coverage.&lt;BR /&gt;
  -and/or-&lt;BR /&gt;
Controller Web GUI is slow to respond after clicking on a web site. &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Cause&lt;/B&gt;&lt;BR /&gt;
A vulnerability (&lt;A href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3192" target="_blank" rel="nofollow noreferrer noopener"&gt;CVE-2011-3192&lt;/A&gt;) patch update has broken a section of the Apache functionality, causing certain requests to use all of the HTTPD CPU cycles. &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Solution&lt;/B&gt;&lt;BR /&gt;
This is fixed as of f/w 8.21.07.0006, with a more complete fix as of f/w 8.21.08.0005. &lt;BR /&gt;
&lt;BR /&gt;
Upgrade to firmware 8.21.08.0005 or higher.&lt;BR /&gt;
&lt;A href="https://extranet.enterasys.com/downloads/Pages/WirelessControllers.aspx" target="_blank" rel="nofollow noreferrer noopener"&gt;Release notes&lt;/A&gt; state, in the 'Changes in 8.21.07.0006' section:&lt;BR /&gt;
&lt;DIV class="threadCode"&gt;&lt;B&gt;code:&lt;/B&gt;&lt;PRE spellcheck="false"&gt;wns0009142&lt;/PRE&gt;&lt;/DIV&gt;  &lt;DIV class="threadCode"&gt;&lt;B&gt;code:&lt;/B&gt;&lt;PRE spellcheck="false"&gt;Solution to protect against denial of service attack disallows partial gets as explained in Known Issues section.&lt;/PRE&gt;&lt;/DIV&gt;&lt;BR /&gt;
Release notes state, in the 'Changes in 8.21.08.0005' section: &lt;BR /&gt;
&lt;DIV class="threadCode"&gt;&lt;B&gt;code:&lt;/B&gt;&lt;PRE spellcheck="false"&gt;wns0009142&lt;/PRE&gt;&lt;/DIV&gt;  &lt;DIV class="threadCode"&gt;&lt;B&gt;code:&lt;/B&gt;&lt;PRE spellcheck="false"&gt;Solution to protect against denial of service attack by disabling partial gets as explained in KB.&lt;/PRE&gt;&lt;/DIV&gt;&lt;BR /&gt;
&lt;BR /&gt;
The accompanying item in the 'Deployment Notes and Known Issues' section: &lt;BR /&gt;
&lt;B&gt;&lt;/B&gt;&lt;PRE&gt;&lt;B&gt;Wns0009142 – info&lt;/B&gt;&lt;/PRE&gt;&lt;BR /&gt;
&lt;DIV class="threadCode"&gt;&lt;B&gt;code:&lt;/B&gt;&lt;PRE spellcheck="false"&gt;The controller will respond to HTTP requests containing the Range header with a Forbidden (403) error. This is to address current Denial of Service attacks that use the Range header. Range headers are used to download parts of a file through HTTP. They are not useful when dealing with the controller since most of its HTTP-downloadable files are small (e.g. graphics) or have a short lifetime (e.g. logs).&lt;/PRE&gt;&lt;/DIV&gt;</description>
    <pubDate>Sat, 09 Nov 2013 06:43:00 GMT</pubDate>
    <dc:creator>FAQ_User</dc:creator>
    <dc:date>2013-11-09T06:43:00Z</dc:date>
    <item>
      <title>IdentiFi Wireless Controller f/w 8.21.06.0006 reporting High CPU Utilization for HTTPD Process</title>
      <link>https://community.extremenetworks.com/t5/faqs/identifi-wireless-controller-f-w-8-21-06-0006-reporting-high-cpu/m-p/46466#M397</link>
      <description>Article ID: 15085 &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Products&lt;/B&gt;&lt;BR /&gt;
C20, C25, C4110, C5110, C5210, V2110; firmware 8.11.01.0161 through 8.21.06.0006&lt;BR /&gt;
IdentiFi (formerly Enterasys, HiPath) Wireless Controller &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Symptoms&lt;/B&gt;&lt;BR /&gt;
Users are unable to connect to the Wireless network.&lt;BR /&gt;
  -and/or-&lt;BR /&gt;
Overall client performance issues, such as poor connections, dropped connections, or spotty coverage.&lt;BR /&gt;
  -and/or-&lt;BR /&gt;
Controller Web GUI is slow to respond after clicking on a web site. &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Cause&lt;/B&gt;&lt;BR /&gt;
A vulnerability (&lt;A href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3192" target="_blank" rel="nofollow noreferrer noopener"&gt;CVE-2011-3192&lt;/A&gt;) patch update has broken a section of the Apache functionality, causing certain requests to use all of the HTTPD CPU cycles. &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Solution&lt;/B&gt;&lt;BR /&gt;
This is fixed as of f/w 8.21.07.0006, with a more complete fix as of f/w 8.21.08.0005. &lt;BR /&gt;
&lt;BR /&gt;
Upgrade to firmware 8.21.08.0005 or higher.&lt;BR /&gt;
&lt;A href="https://extranet.enterasys.com/downloads/Pages/WirelessControllers.aspx" target="_blank" rel="nofollow noreferrer noopener"&gt;Release notes&lt;/A&gt; state, in the 'Changes in 8.21.07.0006' section:&lt;BR /&gt;
&lt;DIV class="threadCode"&gt;&lt;B&gt;code:&lt;/B&gt;&lt;PRE spellcheck="false"&gt;wns0009142&lt;/PRE&gt;&lt;/DIV&gt;  &lt;DIV class="threadCode"&gt;&lt;B&gt;code:&lt;/B&gt;&lt;PRE spellcheck="false"&gt;Solution to protect against denial of service attack disallows partial gets as explained in Known Issues section.&lt;/PRE&gt;&lt;/DIV&gt;&lt;BR /&gt;
Release notes state, in the 'Changes in 8.21.08.0005' section: &lt;BR /&gt;
&lt;DIV class="threadCode"&gt;&lt;B&gt;code:&lt;/B&gt;&lt;PRE spellcheck="false"&gt;wns0009142&lt;/PRE&gt;&lt;/DIV&gt;  &lt;DIV class="threadCode"&gt;&lt;B&gt;code:&lt;/B&gt;&lt;PRE spellcheck="false"&gt;Solution to protect against denial of service attack by disabling partial gets as explained in KB.&lt;/PRE&gt;&lt;/DIV&gt;&lt;BR /&gt;
&lt;BR /&gt;
The accompanying item in the 'Deployment Notes and Known Issues' section: &lt;BR /&gt;
&lt;B&gt;&lt;/B&gt;&lt;PRE&gt;&lt;B&gt;Wns0009142 – info&lt;/B&gt;&lt;/PRE&gt;&lt;BR /&gt;
&lt;DIV class="threadCode"&gt;&lt;B&gt;code:&lt;/B&gt;&lt;PRE spellcheck="false"&gt;The controller will respond to HTTP requests containing the Range header with a Forbidden (403) error. This is to address current Denial of Service attacks that use the Range header. Range headers are used to download parts of a file through HTTP. They are not useful when dealing with the controller since most of its HTTP-downloadable files are small (e.g. graphics) or have a short lifetime (e.g. logs).&lt;/PRE&gt;&lt;/DIV&gt;</description>
      <pubDate>Sat, 09 Nov 2013 06:43:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/faqs/identifi-wireless-controller-f-w-8-21-06-0006-reporting-high-cpu/m-p/46466#M397</guid>
      <dc:creator>FAQ_User</dc:creator>
      <dc:date>2013-11-09T06:43:00Z</dc:date>
    </item>
  </channel>
</rss>

