Can I clarify that the WLSE is likely to report a MAC Spoofing event if user1 logs off a wireless enabled laptop, then user2 logs on.
The text from the manual quotes;
"Whenever the WDS detects an authentication taking place for a known MAC address, it verifies that the same UserId is being used. If the UserId does not properly match, the authentication is rejected."