<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Rogue containment with deauthentication frames ? in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/rogue-containment-with-deauthentication-frames/m-p/2169266#M26329</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Scott,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then is what I thought, but I don't understand why we shouldn't use this mitigation if a rogue AP is inside our buliding &lt;SPAN style="font-size: 10pt;"&gt;WIPS have traditionally used deauthentication frames as rogue containment measures. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Now that MFP-protected stations discard frames that fail the MIC, WIPS may have to come up with some new ways of booting rogue devices. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Anybody knows new methods?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 02 Mar 2013 14:42:51 GMT</pubDate>
    <dc:creator>Alejandro Cadarso Cerdeirina</dc:creator>
    <dc:date>2013-03-02T14:42:51Z</dc:date>
    <item>
      <title>Rogue containment with deauthentication frames ?</title>
      <link>https://community.cisco.com/t5/wireless/rogue-containment-with-deauthentication-frames/m-p/2169261#M26324</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the last WLC releases and APs from other vendors are Introducing support for the &lt;STRONG&gt;802.11w&lt;/STRONG&gt; standard as&amp;nbsp; defined by the Management Frame Protection (MFP) service This implies that&amp;nbsp; Disassociation, Deauthentication, and Robust Action frames increase&amp;nbsp; Wi-Fi network security by protecting the management frames from being&amp;nbsp; spoofed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does this mean that containment using over-the-air de-authentication frames to temporarily interrupt service on a rogue device is not possible if the device and clients associated to it use 802.11w?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 06:39:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/rogue-containment-with-deauthentication-frames/m-p/2169261#M26324</guid>
      <dc:creator>Alejandro Cadarso Cerdeirina</dc:creator>
      <dc:date>2021-07-04T06:39:28Z</dc:date>
    </item>
    <item>
      <title>Re: Rogue containment with deauthentication frames ?</title>
      <link>https://community.cisco.com/t5/wireless/rogue-containment-with-deauthentication-frames/m-p/2169262#M26325</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That's what they say. There are many reference materials out there. Here is one.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.cisco.com/en/US/partner/docs/wireless/mse/3350/release/notes/mse7_3_101_0.html" target="_blank"&gt;http://www.cisco.com/en/US/partner/docs/wireless/mse/3350/release/notes/mse7_3_101_0.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 02 Mar 2013 02:44:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/rogue-containment-with-deauthentication-frames/m-p/2169262#M26325</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2013-03-02T02:44:19Z</dc:date>
    </item>
    <item>
      <title>Rogue containment with deauthentication frames ?</title>
      <link>https://community.cisco.com/t5/wireless/rogue-containment-with-deauthentication-frames/m-p/2169263#M26326</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't see any reference to 802.1w in the link you post&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know this can be done, I've done it many times myself, with cisco and other vendors, BUT my question is &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;is it possible when the rogue AP we try to mitigate is using IEEE 802.11w-2009&amp;nbsp; with their clients?&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 02 Mar 2013 10:47:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/rogue-containment-with-deauthentication-frames/m-p/2169263#M26326</guid>
      <dc:creator>Alejandro Cadarso Cerdeirina</dc:creator>
      <dc:date>2013-03-02T10:47:02Z</dc:date>
    </item>
    <item>
      <title>Re: Rogue containment with deauthentication frames ?</title>
      <link>https://community.cisco.com/t5/wireless/rogue-containment-with-deauthentication-frames/m-p/2169264#M26327</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry wrong link&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://books.google.com/books?id=D4u6ctj9KcYC&amp;amp;pg=PA416&amp;amp;lpg=PA416&amp;amp;dq=802.11w+protect+against+containment&amp;amp;source=bl&amp;amp;ots=nFc7kW5O9p&amp;amp;sig=rbXSP3ltOIY08Ir7WkwRDDBsPuw&amp;amp;hl=en&amp;amp;sa=X&amp;amp;ei=gwoyUdC1L9OHqwGdsoGIBQ&amp;amp;ved=0CDYQ6AEwAQ" target="_blank"&gt;http://books.google.com/books?id=D4u6ctj9KcYC&amp;amp;pg=PA416&amp;amp;lpg=PA416&amp;amp;dq=802.11w+protect+against+containment&amp;amp;source=bl&amp;amp;ots=nFc7kW5O9p&amp;amp;sig=rbXSP3ltOIY08Ir7WkwRDDBsPuw&amp;amp;hl=en&amp;amp;sa=X&amp;amp;ei=gwoyUdC1L9OHqwGdsoGIBQ&amp;amp;ved=0CDYQ6AEwAQ&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.cwnp.com/cwnp_wifi_blog/wireless-lan-security-and-ieee-802-11w/" target="_blank"&gt;http://www.cwnp.com/cwnp_wifi_blog/wireless-lan-security-and-ieee-802-11w/&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 02 Mar 2013 14:20:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/rogue-containment-with-deauthentication-frames/m-p/2169264#M26327</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2013-03-02T14:20:10Z</dc:date>
    </item>
    <item>
      <title>Re: Rogue containment with deauthentication frames ?</title>
      <link>https://community.cisco.com/t5/wireless/rogue-containment-with-deauthentication-frames/m-p/2169265#M26328</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The one thing is that you should never use containment. If a rouge device is inside your building and affecting your wireless, you should find it and remove it. Now if your APs are being contained, this should help as it will not work, but both AP and client must support it.&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 02 Mar 2013 14:22:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/rogue-containment-with-deauthentication-frames/m-p/2169265#M26328</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2013-03-02T14:22:47Z</dc:date>
    </item>
    <item>
      <title>Re: Rogue containment with deauthentication frames ?</title>
      <link>https://community.cisco.com/t5/wireless/rogue-containment-with-deauthentication-frames/m-p/2169266#M26329</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Scott,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then is what I thought, but I don't understand why we shouldn't use this mitigation if a rogue AP is inside our buliding &lt;SPAN style="font-size: 10pt;"&gt;WIPS have traditionally used deauthentication frames as rogue containment measures. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Now that MFP-protected stations discard frames that fail the MIC, WIPS may have to come up with some new ways of booting rogue devices. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Anybody knows new methods?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 02 Mar 2013 14:42:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/rogue-containment-with-deauthentication-frames/m-p/2169266#M26329</guid>
      <dc:creator>Alejandro Cadarso Cerdeirina</dc:creator>
      <dc:date>2013-03-02T14:42:51Z</dc:date>
    </item>
    <item>
      <title>Re: Rogue containment with deauthentication frames ?</title>
      <link>https://community.cisco.com/t5/wireless/rogue-containment-with-deauthentication-frames/m-p/2169267#M26330</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well what I have seen is that you can be doing a deauth to a neighboring tenant. That's a bad thing especially if they catch you. Now why not just contain rogue APs that are using your SSID? The best way to eliminate rogue APs from your internal network is to find it and get rid if it. Now you can use Cisco ISE and protect the ports so that no one can connect rogue devices to your switch, I think that would be a better way. When doing containment, you really need to use like 3 APs and that would also affect the process of the AP if its also supporting clients. To be honest, I wish they got rid of this because it caused more issue than good. That's my opinion. You accidentally contain a neighbor and have to apologize because they will know its you, or vise versa. So if your worried about rogue APs in your internal network, then make sure your containment policy is only for rouge APs using your SSID. If your out in no where land and you don't have any tenants around you, go ahead an contain whatever you want because you are not doing anything illegal then.&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 02 Mar 2013 15:09:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/rogue-containment-with-deauthentication-frames/m-p/2169267#M26330</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2013-03-02T15:09:29Z</dc:date>
    </item>
  </channel>
</rss>

