cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2706
Views
1
Helpful
5
Replies

Rouge AP with ISE

ppoggi
Cisco Employee
Cisco Employee

Hi team,

do we have ISE best practice for discovering rouge AP?

Regards,

Paolo

1 Accepted Solution

Accepted Solutions

Jason Kunst
Cisco Employee
Cisco Employee

Can you explain more?

Besides ise being populated with a list of MAC address and profiling them? What are you looking for?

You could even authenticate your APs perhaps and secure your wired ports and not allow APs that aren't sanctioned

What about wireless controller rogue AP detection

View solution in original post

5 Replies 5

Jason Kunst
Cisco Employee
Cisco Employee

Can you explain more?

Besides ise being populated with a list of MAC address and profiling them? What are you looking for?

You could even authenticate your APs perhaps and secure your wired ports and not allow APs that aren't sanctioned

What about wireless controller rogue AP detection

Hi Jason,

the idea is to discover and possibly control rouge AP leveraging if possible ISE, apart from known wireless controller capability. I guess profiling is the best option and maybe the latest anomalous endpoint detection feature, isn't it?

Is there any Technotes on this topic?

Thanks,

Paolo

Besides the profiling guide, I will check, don’t think so

https://communities.cisco.com/servlet/JiveServlet/previewBody/68156-102-1-125076/How-To_30_ISE_Profiling_Design_Guide.pdf

Identify the expected corp wireless devices and create a logical profile to restrict/block the non-corp controllers/APs.

hariholla
Cisco Employee
Cisco Employee

The AireOS based Wireless LAN Controllers have built in features to handle Rogue APs. As Jason mentioned, ISE can authenticate Wireless Access points and ensure only the known one's are allowed in the network. If a known AP, changes it profile and if necessary data is made available for ISE, then ISE can flag it as 'Anomalous'

Cheers!

-Hari