Wireless Access

Reply
Contributor I
Posts: 74
Registered: ‎03-21-2012

Rogue LAN Detection

So our rogue detection on the LAN seemed to previously work when we had our user VLANs trunked to our controller. We have noticed and tested that it doesn't seem to detect anymore after we moved all our different areas to new layer 3 networks so we can't trunk layer 2 VLANs to the controller anymore. The AP's are all still in the user VLAN, is the only away to detect properly is to deploy air monitors or is there something else we can do?

 

 

Guru Elite
Posts: 8,467
Registered: ‎09-08-2010

Re: Rogue LAN Detection

Are your APs in the wired user subnets or in dedicated ones?

Tim Cappalli | Aruba Security TME
@timcappalli | timcappalli.me | ACMX #367 / ACCX #480
Contributor I
Posts: 74
Registered: ‎03-21-2012

Re: Rogue LAN Detection

AP’s are in the wired user subnets, that VLAN just isn’t capable of trunking to the controller since it’s in a completely separate layer 3 network.
Guru Elite
Posts: 8,467
Registered: ‎09-08-2010

Re: Rogue LAN Detection

As long as the rogue is connected in a subnet where there is at least 1 AP, it should be detected.

Tim Cappalli | Aruba Security TME
@timcappalli | timcappalli.me | ACMX #367 / ACCX #480
MVP
Posts: 1,310
Registered: ‎11-07-2008

Re: Rogue LAN Detection

Additionally, any local-to-the-network VLANs need to be trunked to the AMs and APs as well so that those APs and AMs can sniff the other VLAN's traffic. Even though the AM or AP will see dot1q tags, they know how to parse and inspect them.

Jerrod Howard
Sr. Techical Marketing Engineer
MVP
Posts: 331
Registered: ‎04-25-2013

Re: Rogue LAN Detection

When the controller sees the MAC address AP via wireless (WiFi) and Wireless (LAN), it is classified as a Rogue AP.

and since the MAC address belong to Layer 2 (VLAN), as said before, you must have at least one AP in each VLAN or better AM trunked with all VLANs to be able to detect Rogue AP

Raouf CHAHBOUNE
ICT Network & Security Engineer
CCNP R/S | CCNA Security | ACMP|ACDX



[If my post is helpful please give kudos, or mark as solved if it answers your post.]
Search Airheads
Showing results for 
Search instead for 
Did you mean: