<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Rogue AP detection in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/rogue-ap-detection/m-p/560410#M16715</link>
    <description>&lt;P&gt;The WLSE have detected rouge APs. Theses APs are high RSSI and have variable channel set. How can i handle it? As i know. WLSE is not able to protect my APs from rogue APs attack, only detect it. Should i use wire LAN? any other solution clear this rogue AP's channel interference? Any advice please. Thanks.&lt;/P&gt;</description>
    <pubDate>Sun, 04 Jul 2021 18:56:39 GMT</pubDate>
    <dc:creator>yong1794</dc:creator>
    <dc:date>2021-07-04T18:56:39Z</dc:date>
    <item>
      <title>Rogue AP detection</title>
      <link>https://community.cisco.com/t5/wireless/rogue-ap-detection/m-p/560410#M16715</link>
      <description>&lt;P&gt;The WLSE have detected rouge APs. Theses APs are high RSSI and have variable channel set. How can i handle it? As i know. WLSE is not able to protect my APs from rogue APs attack, only detect it. Should i use wire LAN? any other solution clear this rogue AP's channel interference? Any advice please. Thanks.&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 18:56:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/rogue-ap-detection/m-p/560410#M16715</guid>
      <dc:creator>yong1794</dc:creator>
      <dc:date>2021-07-04T18:56:39Z</dc:date>
    </item>
    <item>
      <title>Re: Rogue AP detection</title>
      <link>https://community.cisco.com/t5/wireless/rogue-ap-detection/m-p/560411#M16716</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You've got to be careful here .... the WLSE can "shut down" rogue APs by either sending a disconnect to the client, or dropping the offending switch port. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is that the "rogue" APs could be other businesses nearby; if you shut down all the "rogue" APs you may be killing another business' wireless system. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can tell the WLSE that a specific "rogue" is known and acceptable, and it will ignore it for the purposes of reporting. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you APs or antennas are at some altitude (mine are on the fifth &amp;amp; sixth floor), you can pick up other wireless systems from a mile away ... if I tell my system to shut down all rogues, I can be killing systems for quite a distance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IMHO, It would be a good idea to bring up a wireless "Sniffer" and identify the traffic; if it's truely rogue/malicious traffic, then shut it down .... but if it's a neighbor, just tell the system to ignore it. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The "Sniffer" can also give you a good idea of which channels are least congested and have the least interference so you can make adjustments to your system.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At the least, bring up something like Netstumbler (it's free, runs on Windows) or Kismet (it's also free, runs on *nix).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can also run some radio scans from the WLSE. I prefer using an external system. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Good Luck&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Apr 2006 13:08:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/rogue-ap-detection/m-p/560411#M16716</guid>
      <dc:creator>scottmac</dc:creator>
      <dc:date>2006-04-14T13:08:46Z</dc:date>
    </item>
    <item>
      <title>Re: Rogue AP detection</title>
      <link>https://community.cisco.com/t5/wireless/rogue-ap-detection/m-p/560412#M16717</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"but if it's a neighbor, just tell the system to ignore it. "&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also use WLSE and have to manage AP. &lt;/P&gt;&lt;P&gt;AP on the fitfh floor and upper in my bulding detect A LOT of rogue AP and, as a result, there are a lot of fault called "rogue AP".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How could I tell WLSE to ignore it?&lt;/P&gt;&lt;P&gt;I try to acknowledge the faults but they appear again after a couple of days&lt;/P&gt;&lt;P&gt;I try to delete the faults but they appear again too.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe to make these "rogue AP" friendly?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thx U by advance!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Apr 2006 12:54:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/rogue-ap-detection/m-p/560412#M16717</guid>
      <dc:creator>khayhuynh</dc:creator>
      <dc:date>2006-04-25T12:54:03Z</dc:date>
    </item>
    <item>
      <title>Re: Rogue AP detection</title>
      <link>https://community.cisco.com/t5/wireless/rogue-ap-detection/m-p/560413#M16718</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am setting up the WLSE for rogue detection.  I was wondering if I have to put in a WAP in sensor mode and also put in a Wireless IDS?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; mcphere&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Apr 2006 17:24:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/rogue-ap-detection/m-p/560413#M16718</guid>
      <dc:creator>emcpherson</dc:creator>
      <dc:date>2006-04-25T17:24:47Z</dc:date>
    </item>
  </channel>
</rss>

