Specifications
Configuring Rogue Detection Lists
22-8 Rogue Detection and Countermeasures
ToremoveanSSIDfromthepermittedSSIDlist,usethefollowingcommand:
clear rfdetect ssid-list ssid-name
ThefollowingcommandclearsSSIDmycorpfromthepermittedSSIDlist:
RBT-8100# clear rfdetect ssid-list mycorp
success: mycorp is no longer in ssid-list.
Configuring a Client Black List
Theclientblacklistspecifiesclientsthatarenotallowedonthenetwork.MSSdropsallpackets
fromtheclientsontheblacklist.
Bydefault,theclientblacklistisempty.Inadditiontomanuallyconfiguredentries,thelistcan
containentriesaddedbyMSS.MSScanplaceaclient
intheblacklistduetoanassociation,
reassociationordisassociationfloodfromtheclient.
TheclientblacklistappliesonlytotheRoamAboutSwitchonwhichthelistisconfigured.
RoamAboutswitchesdonotshareclientblacklists.
Toaddanentrytothelist,usethefollowingcommand:
set rfdetect black-list mac-addr
Examples
ThefollowingcommandaddsclientMACaddress11:22:33:44:55:66totheblacklist:
RBT-8100# set rfdetect black-list 11:22:33:44:55:66
success: MAC 11:22:33:44:55:66 is now blacklisted.
Todisplaytheclientblacklist,usethefollowingcommand:
show rfdetect black-list
ThefollowingexampleshowstheclientblacklistonRoamAboutSwitch:
RBT-8100# show rfdetect black-list
Total number of entries: 1
Blacklist MAC Type Port TTL
----------------- ----------------- ------- ---
11:22:33:44:55:66 configured - -
11:23:34:45:56:67 assoc req flood 3 25