Hi Simon,
Last night I have been googlin' on the issue and found several tutorials on how to do an attack and ways to detect or avoid them.
An attack can be launched against the mac address of a single client unit or the AP.
But the same attack can also be launched at the broadcast address of the network and then ALL radio's on that network receive the de-auth header and they have to obey and disassociate from the AP and AP disassociates all clients at the same time.
After that all Clients will probably try to authenticate and associate again which creates queues in the network and when the attacker keeps on sending deauth frames the network has not a change to recuperate...
I have been playing with the MT settings last night to see how it is done in ROS but am not 100% done with that. You can set the management frame protection in the main wireless window but also in the access list and connect list.
Since most of my networks also have other vendor's stuff around I think I have to set it on the AP in the access list only (and use "required" option) for each client while for clients that can be done in the main window.
But I did not work 100% last night. Tonight I will play with a bit more (its a live network, that's why the night time. I also have to make sure not loosing the connection to a client due a faulty setting...)
And look at my new post
http://forum.mikrotik.com/viewtopic.php?f=7&t=38798
I hope we get some more reactions on this issue.
R.