Specifications
About Rogues and RF Detection
22-2 Rogue Detection and Countermeasures
About Rogues and RF Detection
RFdetectiondetectsalltheIEEE802.11devicesinaMobilityDomainandcan singleoutthe
unauthorizedrogueaccesspoints.
Rogue Access Points and Clients
Arogueaccesspointisanaccesspointthatisnotauthorizedtooperateinanetwork.Rogueaccess
pointsandtheirclientsunderminethesecurityofanenterprisenetworkbypotentiallyallowing
unchallengedaccesstothenetworkbyanywirelessuserorclientinthephysicalvicinity.Rogue
accesspoints
anduserscanalsointerferewiththeoperationofyourenterprisenetwork.
Rogue Classification
WhenMSSdetectsathird‐partywirelessdevicethatisnotallowedonthenetwork,MSSclassifies
thedeviceasoneofthefollowing:
• Rogue—ThedeviceisintheEnterasysnetworkbutdoesnotbelongthere.
• Interferingdevice—ThedeviceisnotpartoftheEnterasysnetworkbutalsoisnota
rogue.No
clientconnectedtothedevicehasbeendetectedcommunicatingwithanynetworkentity
listedintheforwardingdatabase(FDB)ofanyRASintheMobilityDomain.Althoughthe
interferingdeviceisnotconnectedtoyournetwork,thedevicemightbecausingRF
interferencewithAPradios.
Whenyouenable
countermeasures,youcanspecifywhethertoissuethemagainstroguesand
interferingdevices,oragainstroguesonly.Forexample,ifyoudonotwanttoissue
countermeasuresagainstyourneighbor’swirelessdevices,youcanselecttoissue
countermeasuresagainstroguesonly.RFAuto‐TuningcanautomaticallychangeAPradio
channelsto
workaround interferingdeviceswithoutattackingthosedevices.
Rogue Detection Lists
Roguedetectionlistsspecifythethird‐partydevicesandSSIDsthatMSSallowsonthenetwork,
andthedevicesMSSclassifiesasrogues.Youcanconfigurethefollowingroguedetectionlists:
• PermittedSSIDlist—AlistofSSIDsallowedintheMobilityDomain.MSSgeneratesa
messageifanSSIDthatis
notonthelistisdetected.
• Permittedvendorlist—Alistofthewirelessnetworkingequipmentvendorswhose
equipmentisallowedonthenetwork.Thevendorofapieceofequipmentisidentifiedbythe
OrganizationallyUniqueIdentifier(OUI),whichisthefirstthreebytesoftheequipment’s
MACaddress.MSSgenerates
amessageifanAPorwirelessclientwithanOUIthatisnoton
thelistisdetected.
•Clientblacklist—AlistofMACaddressesofwirelessclientswhoarenotallowedonthe
network.MSSpreventsclientsonthelistfromaccessingthenetworkthroughaRAS.Ifthe
clientisplacedontheblacklistdynamicallybyMSSduetoanassociation,reassociationor
disassociationflood,MSSgeneratesalogmessage.
• Ignorelist—Alistofthird‐partydevicesthat youwanttoexemptfromroguedetection.MSS
doesnotcountdevicesontheignorelistasroguesorinterferin g
devices,anddoesnotissue
countermeasuresagainstthem.