I have recently deployed a 4400 WLC, together with 5-6 Aironet 1000 Lightweight AP in our office premises.
I have configured these AP as air monitor, and plant a test "rouge AP" with no WEP (broadcast SSID) and open authentication wihin the vicinity of the lightweight APs. The test "rouge AP" was physcially connected to the same wired network as the WLC & air-monitor.
Result: The Lightweight APs was able to pick up the the planted test "rouge AP" but unable to determine if these rouge devices is physically connected to our wired network.
This is flabbering.