This gets stranger by the second, so when I look at the rfdomain it indicates there are 8 devices online, when you select the pie chart it show 8, but when you select the rfdomain from the tree view
it shows 6 and two of those are the RFS7k.
If I go to statistics and offline devices it show the units that are offline with one ap connected to a device that I believe is a wired IP polycom phone , I conneted to the AP with a serial cable, and logged in, it then started scrolling messages about IPSpoof
and then showing IPs that are in our Range
"st Mac: 01-00-5E-00-00-FB, Proto = 17.
Jul 04 13:41:17 2017: %DATAPLANE-4-DOSATTACK: IPSPOOF ATTACK: Source IP is Spoo fed : Src IP : 172.17.152.31, Dst IP: 224.0.0.251, Src Mac: F4-F5-D8-AA-DB-66, D st Mac: 01-00-5E-00-00-FB, Proto = 17.
Jul 04 13:41:17 2017: %DATAPLANE-4-DOSATTACK: IPSPOOF ATTACK: Source IP is Spoo fed : Src IP : 172.17.150.53, Dst IP: 224.0.0.251, Src Mac: 50-65-F3-46-48-62, D st Mac: 01-00-5E-00-00-FB, Proto = 17.
Jul 04 13:41:17 2017: %DATAPLANE-4-DOSATTACK: IPSPOOF ATTACK: Source IP is Spoo fed : Src IP : 172.17.146.137, Dst IP: 224.0.0.252, Src Mac: 00-15-5D-90-CA-61,"
The AP is now powered off.
The syslog is still showing %dataplane-4-DOSATTACK:ipspoof attack : source ip is spoofed 10.0.0.138 then mac etc
I have a know working config from the RFS taken on the 26/5/17 when wifi bridge was setup and working, although the bridge is not in place at present.
I'm not sure what to do now, default the primary and backup, fire the config back in then set the cluster back up ?