Installation guide

D-93
D.7.1 Unauthorized Access Point Detection
Unauthorized AP detection is a feature directly integrated into the RF Switch. When enabled, it allows the
switch to monitor the RF environment for unauthorized APs. Unauthorized APs can be reported to the RF
Switch from managed radios configured to perform scanning or from Motorola Mobile Units (MUs) detecting
and reporting visible APs when roaming.
Unauthorized AP scanning is supported on AP100, AP300, AP5131 and AP7131 radios adopted by the RF
Switch and is enabled on a per-radio bases. This allows administrators to scan for APs throughout the
network or specific areas depending on the need. Each AP supports the following scanning modes:
Single Channel Scanning - Managed radios monitor the RF environment on the operating channel while
simultaneously servicing mobile users.
Detector - Managed radios monitors all channels in the regulatory domain but cannot service mobile
users.
When an AP is detected by a managed radio or Motorola MU, the RF Switch will compare the reported MAC
address and ESSID against an allowed AP rules list. Allowed AP rules can be configured on the RF Switch to
exclude trusted or known APs which represent no threat to the network from generating alarms. If a reported
AP is matched by an allow rule, the AP is placed in an approved list and no alarm generated. If a reported AP
is not matched by a rule, the AP is placed in an unapproved list and an alarm generated.
Detected APs remain in the an approved or unapproved list until timed out by the RF Switch. APs that
continued to be detected remain in the approved or unapproved list while APs no longer reported are
removed from a list once the configured time-out period has expired.