<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Rogue APs/Clients in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/rogue-aps-clients/m-p/1979813#M15194</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Question 1: No. Enabling RLDP does not make you lose connectivity of local or HREAP or even bridge APs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This link will be helpful to you: &lt;A href="http://www.cisco.com/en/US/tech/tk722/tk809/technologies_white_paper09186a0080722d8c.shtml"&gt;http://www.cisco.com/en/US/tech/tk722/tk809/technologies_white_paper09186a0080722d8c.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did not get your second questoin, what is your concern exactly? Where you see ad hoc rogues? WLC or WCS?&lt;BR /&gt;can you please clarify more?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Amjad&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 30 May 2012 11:43:34 GMT</pubDate>
    <dc:creator>Amjad Abdullah</dc:creator>
    <dc:date>2012-05-30T11:43:34Z</dc:date>
    <item>
      <title>Rogue APs/Clients</title>
      <link>https://community.cisco.com/t5/wireless/rogue-aps-clients/m-p/1979812#M15193</link>
      <description>&lt;P&gt;A couple of quick questions here (5508 WLC, 1142N APs).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I understand if I enable the AP mode to Rogue Detector from the details page of the AP, the AP stops accepting requests and is now looking for rogue items on the wired network. Is this the same when I enable Rogue Location Discovery Protocol? Will I lose the wireless functionality of all of my APs on the controller?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Next question, when I look at the Rogue Summary on the Monitoring page I see three Adhoc Rogue devices. When I select the Detail link only one shows. I remember the other two were HP mutifuction devices with WIFI enabled but I cannot retrieve that information anymore. Ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 05:13:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/rogue-aps-clients/m-p/1979812#M15193</guid>
      <dc:creator>jpgleason</dc:creator>
      <dc:date>2021-07-04T05:13:30Z</dc:date>
    </item>
    <item>
      <title>Rogue APs/Clients</title>
      <link>https://community.cisco.com/t5/wireless/rogue-aps-clients/m-p/1979813#M15194</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Question 1: No. Enabling RLDP does not make you lose connectivity of local or HREAP or even bridge APs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This link will be helpful to you: &lt;A href="http://www.cisco.com/en/US/tech/tk722/tk809/technologies_white_paper09186a0080722d8c.shtml"&gt;http://www.cisco.com/en/US/tech/tk722/tk809/technologies_white_paper09186a0080722d8c.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did not get your second questoin, what is your concern exactly? Where you see ad hoc rogues? WLC or WCS?&lt;BR /&gt;can you please clarify more?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Amjad&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 May 2012 11:43:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/rogue-aps-clients/m-p/1979813#M15194</guid>
      <dc:creator>Amjad Abdullah</dc:creator>
      <dc:date>2012-05-30T11:43:34Z</dc:date>
    </item>
    <item>
      <title>Rogue APs/Clients</title>
      <link>https://community.cisco.com/t5/wireless/rogue-aps-clients/m-p/1979814#M15195</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have a standalone 5508 WLC. On the Monitor/Summary page, to the right there is the Rogue Summary section. My third line item is Adhoc Rogues and I have three listed. When I select the Details link only one shows up. I remember checking this a week ago and seeing some HP devices (assuming they are printers with wireless functionality), but I cannot retrieve this information via GUI or CLI.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not overly worried about getting this information back, but if someone from management asks about it I would like to give them a proper answer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 May 2012 16:37:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/rogue-aps-clients/m-p/1979814#M15195</guid>
      <dc:creator>jpgleason</dc:creator>
      <dc:date>2012-05-30T16:37:59Z</dc:date>
    </item>
    <item>
      <title>Re: Rogue APs/Clients</title>
      <link>https://community.cisco.com/t5/wireless/rogue-aps-clients/m-p/1979815#M15196</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can look in left column in monitor tab in wlc gui. There is a list to monitor rogues ( rogue aps, ad hoc rogues, friendly rogues....etc).&lt;/P&gt;&lt;P&gt;I am not sure if WLC keeps history of rogues that detected earlier but currently not detected. AFAIK you can only display rogues that currently detected.&lt;/P&gt;&lt;P&gt;Check from the mentioned locaion above and let us know if it answers your concern&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Amjad&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 May 2012 18:41:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/rogue-aps-clients/m-p/1979815#M15196</guid>
      <dc:creator>Amjad Abdullah</dc:creator>
      <dc:date>2012-05-30T18:41:03Z</dc:date>
    </item>
    <item>
      <title>Rogue APs/Clients</title>
      <link>https://community.cisco.com/t5/wireless/rogue-aps-clients/m-p/1979816#M15197</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;When I select the Details link only one shows up. I remember checking this a week ago and seeing some HP devices (assuming they are printers with wireless functionality), but I cannot retrieve this information via GUI or CLI.&lt;/PRE&gt;&lt;P&gt;WLC doesn't keep history. If it's the list then the WLC "saw" the rogue clients.&amp;nbsp; If it's not there, then it's either turned off, signal's too weak, or someone's done some "Action" to it. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 May 2012 22:39:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/rogue-aps-clients/m-p/1979816#M15197</guid>
      <dc:creator>Leo Laohoo</dc:creator>
      <dc:date>2012-05-30T22:39:34Z</dc:date>
    </item>
    <item>
      <title>Rogue APs/Clients</title>
      <link>https://community.cisco.com/t5/wireless/rogue-aps-clients/m-p/1979817#M15198</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you guys, both are good answers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On another note, I have a company in a building next to ours and their WIFI range is bleeding over and my WLC is picking them up. Right now I have just set it up as contained. My new question is, they are not friendly or malicious... what is the benefit or harm of classifiying these "rogue APs" as friendly or malicious? I get malicious if it is truly an AP and/or client attacking my network but since these devices are not "authorized" as best practice should I just mark them as malicious? I am talking about up to 40 that are being detected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 May 2012 15:47:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/rogue-aps-clients/m-p/1979817#M15198</guid>
      <dc:creator>jpgleason</dc:creator>
      <dc:date>2012-05-31T15:47:37Z</dc:date>
    </item>
    <item>
      <title>Re: Rogue APs/Clients</title>
      <link>https://community.cisco.com/t5/wireless/rogue-aps-clients/m-p/1979818#M15199</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;On another note, I have a company in a building next to ours and their WIFI range is bleeding over and my WLC is picking them up. Right now I have just set it up as contained.&lt;/PRE&gt;&lt;P&gt;NOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOO!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;&lt;SPAN style="color: #000000;"&gt;Don't do that!&amp;nbsp; &lt;/SPAN&gt;You MAY be liable for criminal offenses. &lt;/STRONG&gt;&lt;/SPAN&gt; Containing a legitimate wi-fi signal (even though it ain't yours) can be constitued as "jamming".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Either classify it as "Unclassified" or "Friendly"/"External".&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 May 2012 22:42:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/rogue-aps-clients/m-p/1979818#M15199</guid>
      <dc:creator>Leo Laohoo</dc:creator>
      <dc:date>2012-05-31T22:42:54Z</dc:date>
    </item>
    <item>
      <title>Re: Rogue APs/Clients</title>
      <link>https://community.cisco.com/t5/wireless/rogue-aps-clients/m-p/1979819#M15200</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have heard of the liability story, but I have never heard of anybody actually being prosecuted for it, let alone proven that it is deliberate. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, setting it to Friendly External will allow your APs to avoid their channels and reduce power to prevent interference. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The question is, of course, is your neighbor doing the same, or are they also "containing" your AP's?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 02 Jun 2012 14:38:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/rogue-aps-clients/m-p/1979819#M15200</guid>
      <dc:creator>mstrz</dc:creator>
      <dc:date>2012-06-02T14:38:47Z</dc:date>
    </item>
    <item>
      <title>Re: Rogue APs/Clients</title>
      <link>https://community.cisco.com/t5/wireless/rogue-aps-clients/m-p/1979820#M15201</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;The question is, of course, is your neighbor doing the same, or are they also "containing" your AP's?&lt;/PRE&gt;&lt;P&gt;Not alot of enterprise-grade wireless vendors have the option to contain. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only time I've "contained" an SSID (and I've done quiet a few) is when I am more than 100% sure the offender is INSIDE my premises.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;I have heard of the liability story, but I have never heard of anybody actually being prosecuted for it, let alone proven that it is deliberate.&lt;/PRE&gt;&lt;P&gt; I have no idea what country you are in but if you are in America, anyone can be sued.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 03 Jun 2012 01:00:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/rogue-aps-clients/m-p/1979820#M15201</guid>
      <dc:creator>Leo Laohoo</dc:creator>
      <dc:date>2012-06-03T01:00:33Z</dc:date>
    </item>
    <item>
      <title>Re: Rogue APs/Clients</title>
      <link>https://community.cisco.com/t5/wireless/rogue-aps-clients/m-p/1979821#M15202</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Q1 ans:&lt;/P&gt;&lt;P&gt;#Both are different technique to find rogue on wire. &lt;/P&gt;&lt;P&gt;#Rogue detector is an AP mode that is applicable per AP.&lt;/P&gt;&lt;P&gt;#RLDP is an global feature that is applicable on AP modes - local, hreap &amp;amp; monitor. Security&amp;gt;&amp;gt; WPS&amp;gt;&amp;gt; General&amp;gt;&amp;gt; RLDP&amp;gt;&amp;gt; drop down menu.&lt;/P&gt;&lt;P&gt;#AP on Rogue Detector mode(listens arp on wire) is not similar to RLDP(that uses wireless). &lt;/P&gt;&lt;P&gt;#AP on Rogue Detector mode will not enable their Radios, so wireless client connection is not possible. The AP will be connected to trunk port of the switch and listens for arp entries on all VLANs, it compares the arp entry against Rogue AP &amp;amp; client info collected by WLC through APs, if it matches then it will make rogue on wire. its not very accurate method.&lt;/P&gt;&lt;P&gt;#AP on RLDP serves client but don't enable this feature on Local/hreap mode AP servicing voice clients(since AP goes off channel and connect to rogue AP that interrupts client service), use dedicated Monitor mode AP for this purpose. When RLDP feature is enabled cisco AP act as wireless client and connect to rogue AP and ping the management interface of WLC, on reply the Rogue AP will be marked as 'Rogue on wire'.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/ps6366/products_tech_note09186a0080b40901.shtml" rel="nofollow"&gt;http://www.cisco.com/en/US/products/ps6366/products_tech_note09186a0080b40901.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Q2 ans:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check First &amp;amp; Last Time Reported On WCS/NCS that stores the history of Rogues.&lt;/P&gt;&lt;P&gt;If you've external trap server setup then it should be there as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Security&amp;gt;&amp;gt; WPS&amp;gt;&amp;gt; General&amp;gt;&amp;gt; Expiration Timeout for Rogue AP and Rogue Client entries - configurable between 240 &amp;amp; 3600 secs. If the rogue is not reported/refreshed with in this time frame then it will get deleted from WLC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Q3 ans:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is suggested to talk to them to reduce their AP power levels if they're seen very high.&lt;/P&gt;&lt;P&gt;If your client talks to their AP(which is detected as Rogue by WLC) then your own client will be marked as rogue client.&lt;/P&gt;&lt;P&gt;Enable MFP - global Infrastructure mfp for AP &amp;amp; per wlan mfp for Client as mandatory to avoid attacks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 03 Jun 2012 08:45:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/rogue-aps-clients/m-p/1979821#M15202</guid>
      <dc:creator>Saravanan Lakshmanan</dc:creator>
      <dc:date>2012-06-03T08:45:33Z</dc:date>
    </item>
  </channel>
</rss>

