User Guide

Table Of Contents
542 Rogue Detection and Countermeasures
320657-A
Countermeasures
You can enable WSS Software to use countermeasures against rogues. Countermeasures consist of packets that interfere
with a client’s ability to use the rogue.
Countermeasures are disabled by default. You can enable them on an individual radio-profile basis. When you enable
them, all devices of interest that are not in the known devices list become viable targets for countermeasures. The
Mobility Domain’s seed switch automatically selects individual radios to send the countermeasure packets.
Summary of Rogue Detection Features
Table 33 lists the rogue detection features in WSS Software.
Table 33: Rogue Detection Features
Rogue Detection
Feature
Description
Applies To
Third-Party
APs
Clients
Classification WSS Software can classify third-party
APs as rogues or interfering devices. A
rogue is a third-party AP whose MAC
address WSS Software knows. An
interfering device does not have a
MAC address known to WSS
Software.
WSS Software can detect rogue clients,
locate their APs, and issue
countermeasures against the APs.
Yes Yes
Permitted vendor list List of OUIs to allow on the network.
An OUI is the first three octets of a
MAC address and uniquely identifies
an AP’s or client’s vendor.
Yes No
Permitted SSID list List of SSIDs allowed on the network.
WSS Software can issue
countermeasures against third-party
APs sending traffic for an SSID that is
not on the list.
Yes No
Client black list List of client MAC addresses that are
not allowed on the wireless network.
WSS Software drops all packets from
these clients.
No Yes
Attack list List of AP MAC addresses to attack.
WSS Software can issue
countermeasures against these APs
whenever they are detected on the
network.
Yes No