AP Overloaded
WiFi Manager raises this alarm when it sees an Access point rejecting the request
to associate by a new wireless client because of overloaded condition.
When does this overloaded condition arise ?
Access points maintains an Association table which has the state information
of all the associated mobile clients. When this table reaches the permitted
level, the Access point will start rejecting requests for new associations.
What are the possible reasons for such overloaded condition and what can
the WLAN Administrators do about it ?
- Really heavy load from legitimate clients: Access Points in densely
populated WiFi user areas face such overloading. This is normal, having additional
Access points in those areas can solve this problem. Sometimes this can also
be because of the Access point only allowed to accept certain number of associations,
in such cases changing their configuration suitable will help.
- Denial of service attack using fake associations: If the AP is not
really overloaded but has been made to reject clients, then it can be because
of denial of service attack. Attackers using a WiFi laptop and opensource
tools can cause such problems. Look for other DoS alarms such as deauthentication
flood, authentication flood, association flood etc., for the overloaded AP.
If there are more DoS alarms raised for the same AP, locate and fix the attackers
to make the AP normal.