Installation guide
Overview
1-26
1.2.5.9 Rogue AP Detection
The switch supports the following rogue AP detection mechanisms:
• Motorola RFMS Support
• RF scan by Access Port on all channels
• SNMP Trap on discovery
• Authorized AP Lists
• Rogue AP Report
• Motorola RFMS Support
RF scan by access port (on one channel) requires an access port to assist in Rogue AP detection. It functions
as follows:
• The switch sends a new configuration message to the adopted AP informing it to detect Rogue APs.
• The access port listens for beacons on its present channel.
• It passes the beacons to the switch as it receives them without any modification.
• The switch processes these beacon messages to generate the list of APs
The process of detecting a Rogue AP is non-disruptive and none of the MU are disassociated during this
process. The access port will only scan on its present channel. An AP300 provides this support.
By choosing this option for detection, all capable access ports are polled for getting the information. You can
configure how frequently this is performed.
RF scan by Access Port on all channels
This process uses Auto Channel Select (called Detector AP assist) to scan for Rogue APs on all available
channels. It functions as follows:
• The switch sends a configuration message (with the ACS bit set and channel dwell time) to the access
port.
• An access port starts scanning each channel and passes the beacons it hears on each channel to the
switch.
• An access port resets itself after scanning all channels.
• An switch then processes this information
The process of detecting a Rogue AP is disruptive, as connected MUs loose association. MUs need to
reconnect once the access port resets.
SNMP Trap on discovery
An SNMP trap is sent for each detected and Rogue AP. Rogue APs are only detected, and notification is
provided via a SNMP trap.
NOTE The Motorola RF Management Software is recommended to plan the deployment
of the switch. Motorola RFMS can help optimize the positioning and configuration
of a switch in respect to a WLAN’s MU throughput requirements and can help
detect rogue devices. For more information, refer to the Motorola Web site.
NOTE Wired side scanning for Rogue APs using WNMP is not supported. Similarly,
Radius lookup for approved AP is not provided.