<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to manage unclassified rogue AP's? in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/how-to-manage-unclassified-rogue-ap-s/m-p/2172602#M14923</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, but t&lt;SPAN style="font-size: 10pt;"&gt;he problem is that if the Friendly&amp;nbsp; AP changes its SSID by one SSID of your network (managed SSID) is not detected &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;as Malicious.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;And with this change this Friendly AP is a thread and should be detected as Malicious but it's not&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 10 Apr 2013 11:30:57 GMT</pubDate>
    <dc:creator>jmprats</dc:creator>
    <dc:date>2013-04-10T11:30:57Z</dc:date>
    <item>
      <title>How to manage unclassified rogue AP's?</title>
      <link>https://community.cisco.com/t5/wireless/how-to-manage-unclassified-rogue-ap-s/m-p/2172600#M14921</link>
      <description>&lt;P&gt; What am I supposed to do with unclassified rogue AP?&lt;/P&gt;&lt;P&gt;I understand that if they don't look a thread I can mark them as "Friendly External" to no receive more alarms about them. Is it ok?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is what happens&amp;nbsp; if this external Friendly AP change the SSID for a Managed SSID (an SSID is using our controller). Then, this AP is a threat, but is not longer detected for the controller&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it a bug?&lt;/P&gt;&lt;P&gt;or am I not managing unclassified Rogue correctly?&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 06:53:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/how-to-manage-unclassified-rogue-ap-s/m-p/2172600#M14921</guid>
      <dc:creator>jmprats</dc:creator>
      <dc:date>2021-07-04T06:53:19Z</dc:date>
    </item>
    <item>
      <title>Re: How to manage unclassified rogue AP's?</title>
      <link>https://community.cisco.com/t5/wireless/how-to-manage-unclassified-rogue-ap-s/m-p/2172601#M14922</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't even bother with these alerts to be honest. You can mark them friendly just so you don't get the alerts if you want. Just depends on what you want to see or ignore:)&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Apr 2013 11:24:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/how-to-manage-unclassified-rogue-ap-s/m-p/2172601#M14922</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2013-04-10T11:24:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to manage unclassified rogue AP's?</title>
      <link>https://community.cisco.com/t5/wireless/how-to-manage-unclassified-rogue-ap-s/m-p/2172602#M14923</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, but t&lt;SPAN style="font-size: 10pt;"&gt;he problem is that if the Friendly&amp;nbsp; AP changes its SSID by one SSID of your network (managed SSID) is not detected &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;as Malicious.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;And with this change this Friendly AP is a thread and should be detected as Malicious but it's not&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Apr 2013 11:30:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/how-to-manage-unclassified-rogue-ap-s/m-p/2172602#M14923</guid>
      <dc:creator>jmprats</dc:creator>
      <dc:date>2013-04-10T11:30:57Z</dc:date>
    </item>
    <item>
      <title>How to manage unclassified rogue AP's?</title>
      <link>https://community.cisco.com/t5/wireless/how-to-manage-unclassified-rogue-ap-s/m-p/2172603#M14924</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;this issue seen on what WLC code?&lt;/P&gt;&lt;P&gt;display the screenshot of Rogue rules.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 19 May 2013 06:48:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/how-to-manage-unclassified-rogue-ap-s/m-p/2172603#M14924</guid>
      <dc:creator>Saravanan Lakshmanan</dc:creator>
      <dc:date>2013-05-19T06:48:54Z</dc:date>
    </item>
    <item>
      <title>How to manage unclassified rogue AP's?</title>
      <link>https://community.cisco.com/t5/wireless/how-to-manage-unclassified-rogue-ap-s/m-p/2172604#M14925</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Version code 7.0.235.3&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/0/9/4/139490-roguerules.png" class="jive-image" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 May 2013 06:54:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/how-to-manage-unclassified-rogue-ap-s/m-p/2172604#M14925</guid>
      <dc:creator>jmprats</dc:creator>
      <dc:date>2013-05-20T06:54:23Z</dc:date>
    </item>
    <item>
      <title>How to manage unclassified rogue AP's?</title>
      <link>https://community.cisco.com/t5/wireless/how-to-manage-unclassified-rogue-ap-s/m-p/2172605#M14926</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Are you manually classifying as Friendly External?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;If yes then #1 is applicable and what you're seeing is expected. If not then &lt;SPAN style="font-size: 10pt;"&gt;#3 is not happening in your case and how long did you wait once the ssid of the rogue changed to the WLC's management?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#Try, If the AP is removed from friendly rogue list(monitor&amp;gt; Rogue&amp;gt; friendly APs) then does it classifies back to original status friendly or malicious as expected. in this case it should classify as malicious once removed from friendly list based on #2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/wireless/controller/7.3/configuration/guide/b_wlc-cg_chapter_0110.html#d116047e9015a1635"&gt;http://www.cisco.com/en/US/docs/wireless/controller/7.3/configuration/guide/b_wlc-cg_chapter_0110.html#d116047e9015a1635&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When the controller receives a rogue report from one of its managed access points, it responds as follows:&lt;/P&gt;&lt;OL style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; line-height: 14.390625px; background-color: #ffffff;"&gt;&lt;LI&gt;&lt;A name="ID4035__li_F4465D07D8A346BE963001504FA04C5F"&gt;&lt;/A&gt;&lt;A name="ID4035__ID4044"&gt;&lt;/A&gt;&lt;STRONG&gt;The controller verifies that the unknown access point is in the friendly MAC address list. If it is, the controller classifies the access point as Friendly.&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A name="ID4035__li_86372FF51853425DB6EBF2D272CAF76B"&gt;&lt;/A&gt;&lt;A name="ID4035__ID4046"&gt;&lt;/A&gt;&lt;STRONG&gt;If the unknown access point is not in the friendly MAC address list, the controller starts applying rogue classification rules.&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A name="ID4035__li_B3568C5A8629427891F18F719A4FEBB0"&gt;&lt;/A&gt;&lt;A name="ID4035__ID4048"&gt;&lt;/A&gt;&lt;STRONG&gt;If the rogue is already classified as Malicious, Alert or Friendly, Internal or External, the controller does not reclassify it automatically. If the rogue is classified differently, the controller reclassifies it automatically only if the rogue is in the Alert state&lt;/STRONG&gt;.&lt;/LI&gt;&lt;LI&gt;&lt;A name="ID4035__li_FB2D131245EA4DE4B9CC287A2C6CB7BA"&gt;&lt;/A&gt;&lt;A name="ID4035__ID4050"&gt;&lt;/A&gt;The controller applies the first rule based on priority. If the rogue access point matches the criteria specified by the rule, the controller classifies the rogue according to the classification type configured for the rule.&lt;/LI&gt;&lt;LI&gt;&lt;A name="ID4035__li_A931ADC2A90243F3AD50582B3BF0D667"&gt;&lt;/A&gt;&lt;A name="ID4035__ID4052"&gt;&lt;/A&gt;If the rogue access point does not match any of the configured rules, the controller classifies the rogue as Unclassified.&lt;/LI&gt;&lt;LI&gt;&lt;A name="ID4035__li_17961D22E18745EA82AD956D050D64F7"&gt;&lt;/A&gt;&lt;A name="ID4035__ID4054"&gt;&lt;/A&gt;The controller repeats the previous steps for all rogue access points.&lt;/LI&gt;&lt;/OL&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 May 2013 09:32:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/how-to-manage-unclassified-rogue-ap-s/m-p/2172605#M14926</guid>
      <dc:creator>Saravanan Lakshmanan</dc:creator>
      <dc:date>2013-05-20T09:32:32Z</dc:date>
    </item>
    <item>
      <title>Olá jmprats.appling that rule</title>
      <link>https://community.cisco.com/t5/wireless/how-to-manage-unclassified-rogue-ap-s/m-p/2172606#M14927</link>
      <description>&lt;P&gt;Olá jmprats.&lt;BR /&gt;&lt;BR /&gt;appling that rule every rogue AP with a signal stronger that -70dBm will be automatically classified as Malicious?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jun 2014 10:15:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/how-to-manage-unclassified-rogue-ap-s/m-p/2172606#M14927</guid>
      <dc:creator>Bruno Dinis</dc:creator>
      <dc:date>2014-06-11T10:15:32Z</dc:date>
    </item>
    <item>
      <title>The identification of Rogue</title>
      <link>https://community.cisco.com/t5/wireless/how-to-manage-unclassified-rogue-ap-s/m-p/2172607#M14928</link>
      <description>&lt;P&gt;The identification of Rogue AP is done by WLC, whereas we could classify the AP either manually or based on set of rules.&lt;/P&gt;&lt;P&gt;The controller would still be able to identify that AP as a Rogue AP. The reason is that the Wireless LAN Controller would look for the Basic Service Set Identifier (BSSID) for that particular AP.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jul 2014 08:06:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/how-to-manage-unclassified-rogue-ap-s/m-p/2172607#M14928</guid>
      <dc:creator>Moin Ilyas</dc:creator>
      <dc:date>2014-07-10T08:06:56Z</dc:date>
    </item>
  </channel>
</rss>

