<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Question on Rogue Detection in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/question-on-rogue-detection/m-p/1965072#M26338</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If roge detection under the AP advanced tab is selected:&lt;/P&gt;&lt;P&gt;- Enabled: the AP will report rogues it finds to the WLC.&lt;/P&gt;&lt;P&gt;- Disabled: the AP will not report any rogues to the WLC regardless of what AP authentication is.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If rogue detection is enabled and AP authentication is:&lt;/P&gt;&lt;P&gt;- None: AP reports rogues it finds to the controller. APs on same mobility group are not reported even if they are on different RF groups.&lt;/P&gt;&lt;P&gt;- AP authentication: AP reports the rogues to the WLC. APs on same mobility group but with different RF groups are also reported as rogues.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Amjad&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 18 Jul 2012 11:29:25 GMT</pubDate>
    <dc:creator>Amjad Abdullah</dc:creator>
    <dc:date>2012-07-18T11:29:25Z</dc:date>
    <item>
      <title>Question on Rogue Detection</title>
      <link>https://community.cisco.com/t5/wireless/question-on-rogue-detection/m-p/1965068#M26334</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a question regarding rogue detection configuration on WLC. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we know that rogue detection can be enabled on a per AP basis under the advanced tab of each AP, starting from code 6.0, and it also supports rogue detection in RF groups when we configure protection type as "AP Authentication" under WLC security tab, which will make APs to authentication frames based on the RF group name, if name is different, then the AP is considered as a rogue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so the question is if we only enable rogue detection on the AP level, however leave the AP authentication selected as "none", how does the AP detect rogues? does that mean if any signal detected is not from the APs connected to the WLC, then this will be considered as a rogue?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;also in the configuration guide, under the section "enable rogue access point detection in RF groups", it says rogue detection will need the AP to be configured as either local or monitor mode, when we also have AP authentication enabled. however if an AP is under h-reap mode, we still able to enable/disable rogue detection under the advanced tab, so how does H-REAP mode APs detect rogues? is that the same method as when AP authentication selected as "none"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks in advance for your help.&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 05:24:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/question-on-rogue-detection/m-p/1965068#M26334</guid>
      <dc:creator>wireless_student</dc:creator>
      <dc:date>2021-07-04T05:24:57Z</dc:date>
    </item>
    <item>
      <title>Question on Rogue Detection</title>
      <link>https://community.cisco.com/t5/wireless/question-on-rogue-detection/m-p/1965069#M26335</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;it is applicable not only for AP Authentication but also even for AP infrastructure mfp.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;does that mean if any signal detected is not from the APs connected to the WLC, then this will be considered as a rogue?&lt;/P&gt;&lt;P&gt;Yes, APs outside cisco WLC and APs that are not on same RF group will be rogues.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if an AP is under h-reap mode, we still able to enable/disable rogue&amp;nbsp; detection under the advanced tab, so how does H-REAP mode APs detect&amp;nbsp; rogues? is that the same method as when AP authentication selected as&amp;nbsp; "none"&lt;/P&gt;&lt;P&gt;If hreap is on connected mode to WLC then yes it detects rogue and report to WLC, on standalone it doesn't work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/ps10315/products_tech_note09186a0080b3690b.shtml"&gt;http://www.cisco.com/en/US/products/ps10315/products_tech_note09186a0080b3690b.shtml&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jul 2012 12:39:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/question-on-rogue-detection/m-p/1965069#M26335</guid>
      <dc:creator>Saravanan Lakshmanan</dc:creator>
      <dc:date>2012-07-17T12:39:15Z</dc:date>
    </item>
    <item>
      <title>Re: Question on Rogue Detection</title>
      <link>https://community.cisco.com/t5/wireless/question-on-rogue-detection/m-p/1965070#M26336</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If APs joinign a cisco WLC detected WIRELESS 802.11 FRAMES that are being send and they do not belong to the WLC to which the AP belongs or any WLC in its mobility group then the source of those frames (source mac address) is considered a rogue AP that has that mac address as a source.&lt;/P&gt;&lt;P&gt;If the detected signal is not a wireless 802.11 frame (just noise, bluetooth...etc) then that is not detected as rogue because the AP does not able to analyze that signal as 802.11 frame and hence does not know the source mac of the sender.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Amjad&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jul 2012 10:04:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/question-on-rogue-detection/m-p/1965070#M26336</guid>
      <dc:creator>Amjad Abdullah</dc:creator>
      <dc:date>2012-07-18T10:04:04Z</dc:date>
    </item>
    <item>
      <title>Question on Rogue Detection</title>
      <link>https://community.cisco.com/t5/wireless/question-on-rogue-detection/m-p/1965071#M26337</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you both for the reply, can you please confirm the below senario as well:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;with rogue detection enabled on AP level, what is the difference between AP authentication configured as "none" and "AP Authentication"? my understanding is that with AP Authentication or MFP enabled under "AP Authentication" field, rogue detection will be verified based on the RF group name, so signal from other RF domain or not from WLC will be considered as rogue, but what if we select AP authentication as "none"? are we still using RF group name to authenticate frames from other APs? or there is another method? if not does that mean rogue detection is DISABLED in this case even when we have it enabled under the advanced tab of the APs? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for your time to clarify this.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jul 2012 11:16:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/question-on-rogue-detection/m-p/1965071#M26337</guid>
      <dc:creator>wireless_student</dc:creator>
      <dc:date>2012-07-18T11:16:38Z</dc:date>
    </item>
    <item>
      <title>Question on Rogue Detection</title>
      <link>https://community.cisco.com/t5/wireless/question-on-rogue-detection/m-p/1965072#M26338</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If roge detection under the AP advanced tab is selected:&lt;/P&gt;&lt;P&gt;- Enabled: the AP will report rogues it finds to the WLC.&lt;/P&gt;&lt;P&gt;- Disabled: the AP will not report any rogues to the WLC regardless of what AP authentication is.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If rogue detection is enabled and AP authentication is:&lt;/P&gt;&lt;P&gt;- None: AP reports rogues it finds to the controller. APs on same mobility group are not reported even if they are on different RF groups.&lt;/P&gt;&lt;P&gt;- AP authentication: AP reports the rogues to the WLC. APs on same mobility group but with different RF groups are also reported as rogues.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Amjad&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jul 2012 11:29:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/question-on-rogue-detection/m-p/1965072#M26338</guid>
      <dc:creator>Amjad Abdullah</dc:creator>
      <dc:date>2012-07-18T11:29:25Z</dc:date>
    </item>
    <item>
      <title>Question on Rogue Detection</title>
      <link>https://community.cisco.com/t5/wireless/question-on-rogue-detection/m-p/1965073#M26339</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; ok, thanks for your reply, so if AP authentication is "none", then even RF group name is different, then AP will NOT report rogues from other WLCs, and WLCs in the same mobility group is the condition for this? becasue it seems AP still reports rogues, and it should report rogue APs from other WLCs which has no relation to the current one (not in mobility group/list, different RF group), then in this case RF group name is not something that the WLC uses to determine the rogue?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jul 2012 12:11:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/question-on-rogue-detection/m-p/1965073#M26339</guid>
      <dc:creator>wireless_student</dc:creator>
      <dc:date>2012-07-18T12:11:30Z</dc:date>
    </item>
    <item>
      <title>Re: Question on Rogue Detection</title>
      <link>https://community.cisco.com/t5/wireless/question-on-rogue-detection/m-p/1965074#M26340</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;ok, thanks for your reply, so if AP authentication is "none", then even RF group name is different, then AP will NOT report rogues from other WLCs, and WLCs in the same mobility group is the condition for this?&lt;BR /&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;WLC mobility group is always a condition to decide if a rogue should be reported or not. If on same mobility group then it is not rogue. if on different mobility group then it is a rogue.&lt;/P&gt;&lt;P&gt;RF group is not always there. you can enable or disable checking it by selecting "none" or "AP authentication". If none then RF group should be similar or else it is reported as a rogue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If mobility group is different then we do not look at RF group and the AP is reported as rogue.&lt;/P&gt;&lt;P&gt;If mobility group is similar then:&lt;/P&gt;&lt;P&gt;- If "none" we do notlook at the RF group and the AP considered not rogue.&lt;/P&gt;&lt;P&gt;- If "AP authentication" then we look at the RF group. if similar then not rogue. if different then rogue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Amjad&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jul 2012 12:27:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/question-on-rogue-detection/m-p/1965074#M26340</guid>
      <dc:creator>Amjad Abdullah</dc:creator>
      <dc:date>2012-07-18T12:27:59Z</dc:date>
    </item>
    <item>
      <title>Question on Rogue Detection</title>
      <link>https://community.cisco.com/t5/wireless/question-on-rogue-detection/m-p/1965075#M26341</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; ahh, ok this makes sense now, thanks a lot for your help!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jul 2012 12:57:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/question-on-rogue-detection/m-p/1965075#M26341</guid>
      <dc:creator>wireless_student</dc:creator>
      <dc:date>2012-07-18T12:57:09Z</dc:date>
    </item>
    <item>
      <title>Question on Rogue Detection</title>
      <link>https://community.cisco.com/t5/wireless/question-on-rogue-detection/m-p/1965076#M26342</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;don't think Mobility group will be a prime factor and it is always RF group since Configuring Mobility group is optional, RF group is mandatory for a WLC. Also, Rogue detection happen over wireless, to show or not to show as rogue is decided by other configuration parameters Ex: Rogue rules, AP auth type, is it in friendly list,.... only exception is with different RF group with same Mobility may still detect as Rogue but won't show bcoz mobility group is the subset of RF group just like other filter parameters.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is recommended to keep RF group name, Mobility group name, AP auth type used similar across all WLCs whose APs ovelapping RF. Same RF group name with different AP auth type will be flagged as Rogue.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jul 2012 15:46:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/question-on-rogue-detection/m-p/1965076#M26342</guid>
      <dc:creator>Saravanan Lakshmanan</dc:creator>
      <dc:date>2012-07-18T15:46:59Z</dc:date>
    </item>
    <item>
      <title>Question on Rogue Detection</title>
      <link>https://community.cisco.com/t5/wireless/question-on-rogue-detection/m-p/1965077#M26343</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; hi Saravanan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ok if mobility group/list configuration is not considered as a factor for rogue detection, can you please help to explain what is the difference between "none" and "AP Authentication" under the AP Authentication configuration?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when we have rogue detection enabled under AP level, does that mean rogues will always be detected, even if ap authentication selected as "none"?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Jul 2012 02:00:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/question-on-rogue-detection/m-p/1965077#M26343</guid>
      <dc:creator>wireless_student</dc:creator>
      <dc:date>2012-07-19T02:00:15Z</dc:date>
    </item>
    <item>
      <title>Question on Rogue Detection</title>
      <link>https://community.cisco.com/t5/wireless/question-on-rogue-detection/m-p/1965078#M26344</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;can anyone please help to confirm what is the difference between "none" and "AP Authentication" under "AP Authentication" configuration option?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;appreciate any comment on this.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Jul 2012 11:43:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/question-on-rogue-detection/m-p/1965078#M26344</guid>
      <dc:creator>wireless_student</dc:creator>
      <dc:date>2012-07-20T11:43:52Z</dc:date>
    </item>
    <item>
      <title>Re: Question on Rogue Detection</title>
      <link>https://community.cisco.com/t5/wireless/question-on-rogue-detection/m-p/1965079#M26345</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Saravanan:&lt;/P&gt;&lt;P&gt;I dont agree. If wlcs on same mobility domain the  aps on different wlcs are not reported as rogues. However, if wlcs on different mobility domain (or mobility domain is not set) then the aps on different wlcs are reported as rogues.&lt;/P&gt;&lt;P&gt;Rogue rules and friendly list are used to classify rogue aps that are reported. While aps on same mobility domain are not reported in the first place.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Amjad&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Jul 2012 16:09:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/question-on-rogue-detection/m-p/1965079#M26345</guid>
      <dc:creator>Amjad Abdullah</dc:creator>
      <dc:date>2012-07-20T16:09:43Z</dc:date>
    </item>
    <item>
      <title>Re: Question on Rogue Detection</title>
      <link>https://community.cisco.com/t5/wireless/question-on-rogue-detection/m-p/1965080#M26346</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Amjad,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Saravanan is correct, its RF group -- not mobility group. I too have made this mistake, as you, until i read the config guide like 20x times ..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See below this may help better explain. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;H2&gt; Enabling Rogue Access Point Detection in RF Groups &lt;/H2&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A name="wp1180350"&gt;&lt;/A&gt; &lt;/P&gt;&lt;P&gt; After you have created an RF group of controllers, you need to configure&amp;nbsp; the access points connected to the controllers to detect rogue access&amp;nbsp; points. The access points will then select the beacon/&lt;BR /&gt;probe-response&amp;nbsp; frames in neighboring access point messages to see if they contain an&amp;nbsp; authentication information element (IE) that matches that of the RF&amp;nbsp; group. If the select is successful, the frames are authenticated.&amp;nbsp; Otherwise, the authorized access point reports the neighboring access&amp;nbsp; point as a rogue, records its BSSID in a rogue table, and sends the&amp;nbsp; table to the controller. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Jul 2012 16:42:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/question-on-rogue-detection/m-p/1965080#M26346</guid>
      <dc:creator>George Stefanick</dc:creator>
      <dc:date>2012-07-20T16:42:19Z</dc:date>
    </item>
    <item>
      <title>Re: Question on Rogue Detection</title>
      <link>https://community.cisco.com/t5/wireless/question-on-rogue-detection/m-p/1965081#M26347</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;#Regards to AP Auth type, Same RF group require to have same AP Auth type - Auth/MFP/none on all WLCs. Different RF group with same auth type or same RF group with different RF group will be flagged as rogue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;should be an easy test if you've two wlc.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Jul 2012 17:44:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/question-on-rogue-detection/m-p/1965081#M26347</guid>
      <dc:creator>Saravanan Lakshmanan</dc:creator>
      <dc:date>2012-07-20T17:44:16Z</dc:date>
    </item>
    <item>
      <title>Re: Question on Rogue Detection</title>
      <link>https://community.cisco.com/t5/wireless/question-on-rogue-detection/m-p/1965082#M26348</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;#Mobility group check is added as subset to delete the rogue, if they're already joined to them to avoid self containment(see exception from prior post)from 7.0 only, prior to that -mobility means nothing to rogue detection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#Mobility happens on wire while RF neighbor/rogue learning happens over wireless is the key difference.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Jul 2012 17:48:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/question-on-rogue-detection/m-p/1965082#M26348</guid>
      <dc:creator>Saravanan Lakshmanan</dc:creator>
      <dc:date>2012-07-20T17:48:20Z</dc:date>
    </item>
    <item>
      <title>Re: Question on Rogue Detection</title>
      <link>https://community.cisco.com/t5/wireless/question-on-rogue-detection/m-p/1965083#M26349</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;George and Saravanan:&lt;/P&gt;&lt;P&gt;Thank you. +5 to each post you both put. Your clarification is very useful to me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What i know from before: mobility group wlcs can communicate and know the ap belongs to any of group wlcs. Hence they know it is not a rogue. If  It is "ap auth" then rf group should be the same. If "none" then rf group if different on same mobility domain then is even not reported.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If anyone can test and confirm that will be appreciated. Because some of the info i got was from Cisco TAC. About cisco doc: they are useful but sometimes not accurate enough and sometime missing information. I became a friend with the wireless doc manager because i report too many problems with the docs &lt;SPAN __jive_emoticon_name="happy"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;So if you can test the mobility domain part that will be great.&lt;/P&gt;&lt;P&gt;Because depending on your explanation if another neighbor network is exist with same RF group name then it will not be reported as a rogue. It does not make sense this way and I think there is a missing part.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you again&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Jul 2012 18:29:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/question-on-rogue-detection/m-p/1965083#M26349</guid>
      <dc:creator>Amjad Abdullah</dc:creator>
      <dc:date>2012-07-20T18:29:28Z</dc:date>
    </item>
    <item>
      <title>Re: Question on Rogue Detection</title>
      <link>https://community.cisco.com/t5/wireless/question-on-rogue-detection/m-p/1965084#M26350</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You should test it and let us know &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Jul 2012 22:16:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/question-on-rogue-detection/m-p/1965084#M26350</guid>
      <dc:creator>George Stefanick</dc:creator>
      <dc:date>2012-07-20T22:16:22Z</dc:date>
    </item>
    <item>
      <title>Re: Question on Rogue Detection</title>
      <link>https://community.cisco.com/t5/wireless/question-on-rogue-detection/m-p/1965085#M26351</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have done some tests regarding rogue detection, and here are some of my findings:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;OL start="1"&gt;&lt;LI&gt;different RF group name, with AP Authentication policy on both WLCs selected to "none": rogue will be detected&lt;BR /&gt;&lt;/LI&gt;&lt;LI&gt;different RF group name with AP Authentication policy on both WLCs selected to "ap-auth": rogue will be detected&lt;BR /&gt;&lt;/LI&gt;&lt;LI&gt;same RF group name wtih AP Authentication policy on both WLCs selected to "none", rogue will not be detected&lt;BR /&gt;&lt;/LI&gt;&lt;LI&gt;same RF group name with AP Authentication policy on both WLCs selected to "ap-auth", rogue will not be detected&lt;BR /&gt;&lt;/LI&gt;&lt;LI&gt;same RF group name with AP Authentication policy on one WLC as "none" and on the other as "ap-auth", rogue will be detected&lt;BR /&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;however I have noticed something that does not seem to be correct. I am only able to see the rogue from one WLC but not the other, for example I have WLCs number 1 and 2, from number 1 I could see radio from WLC number 2 as rogue, however I am not able to see radio on WLC number 1 reported as rogue on WLC number 2, when I configured different RF group name.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;all the above tests are performed with both WLCs in the same mobility list.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so it seems RF group name as well as the AP authentication policy are the factors for reporting rogue APs (plus enable rogue detection on the AP level of course), however I guess the questions still remain are:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;OL start="1"&gt;&lt;LI&gt;what is the difference between enabling "none" and "ap authentication" under AP authentication policy, if we keep this parameter consistent across all WLCs? it appears there is not much of difference however there must be a reason for each option available here.&lt;BR /&gt;&lt;/LI&gt;&lt;LI&gt;if we select AP authentication, then what is the threshold number actually represents? my understanding is that this is the number of times that same radio MAC/BSSID been detected, so to prevent from false alarms, we need to increase this numebr, however in the configuration guide, it says this has something to do with WMM clients as well, can you please advise what is this number stands for and what is the general best practice for this number?&lt;BR /&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks in advance for your time and help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 22 Jul 2012 03:51:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/question-on-rogue-detection/m-p/1965085#M26351</guid>
      <dc:creator>wireless_student</dc:creator>
      <dc:date>2012-07-22T03:51:04Z</dc:date>
    </item>
    <item>
      <title>Re: Question on Rogue Detection</title>
      <link>https://community.cisco.com/t5/wireless/question-on-rogue-detection/m-p/1965086#M26352</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've done some tests as well:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have multiple WLCs on same mobility and same RF groups. AP Auth type set to "none" on all o ft hem. I took one WLC (I'll call it thereafter "My WLC") and changed its RF group name. I also cahnged its AP auth policy to "AP Authentication". All WLCs have same SSIDs configured. I added one extra test SSID on "MY WLC".&lt;/P&gt;&lt;P&gt;The results are:&lt;/P&gt;&lt;P&gt;- The WLC with different RF group name did not mention other APs as rogues. Other APs did not mention my WLC APs as rogues as well.&lt;/P&gt;&lt;P&gt;- There is very high number of AP impersonation detected by "My WLC". other WLCs did not detect ap impersonation. This indicates that other APs on other WLCs try to contain "My WLC" APs. However, "My WLC" does not seem to try impersonating other APs. (it worths to notice that number of APs on "My WLC" is much less than APs on other WLCs).&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/3/5/1/96153-AP-Impersonation.PNG" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- When using "AP authentication", there is a new IE appears in the SSID beacons.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/4/5/1/96154-sniff-Capture.PNG" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The highlighted in blue is that information that could not be interpretted (as seen in highlighted yellow above). This information differs based no the SSID. Different SSID name shows different information. This IE seems to carry the information about the RF group name. If this does not appear when using "none" as AP auth policy then WLCs can not distinguish different RF group names if ap auth set to "none". (because I could not find any RF group info anywhere in the beacon packet. If you know it is exist somewhere else please let us know. So far I assume it is included in this vendor specific IE).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- When I changed the AP auth to "none" the number of AP impersonation reported started to decrease gradually. I'll keep monitoring to see what it will be after couple of hours.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Config guide is very useful. However, sometimes it is extremley stupid. Why?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; well, because if you go to the part that talks about configuring MFP (&lt;A href="http://tiny.cc/un6thw" rel="nofollow"&gt;http://tiny.cc/un6thw&lt;/A&gt;), and if you go to Step 5,&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; you will find that the optoin metnioned in step 5 is not available in the AP. It tells you that to enable or disable MFP&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; validation for specific AP you can do this from under Advanced tab. However, this option is not available under&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Advanced tab. I had a big discussion with TAC about this very long time ago. prompted to doc guys about it but so&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; far nothign changed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Amjad&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 22 Jul 2012 07:23:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/question-on-rogue-detection/m-p/1965086#M26352</guid>
      <dc:creator>Amjad Abdullah</dc:creator>
      <dc:date>2012-07-22T07:23:26Z</dc:date>
    </item>
    <item>
      <title>Re: Question on Rogue Detection</title>
      <link>https://community.cisco.com/t5/wireless/question-on-rogue-detection/m-p/1965087#M26353</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;By now the number of AP impersonations last hour = 0.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 22 Jul 2012 07:59:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/question-on-rogue-detection/m-p/1965087#M26353</guid>
      <dc:creator>Amjad Abdullah</dc:creator>
      <dc:date>2012-07-22T07:59:47Z</dc:date>
    </item>
  </channel>
</rss>

