Wireless Access

 View Only
last person joined: 23 hours ago 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Prevent AP from plugging into LAN

This thread has been viewed 37 times
  • 1.  Prevent AP from plugging into LAN

    Posted Jun 22, 2024 02:50 AM

    Hi everyone :)

    I discovered that there is a rogue AP plugged into the Cisco switch, but I can't tell which switch port the rogue AP is plugged into. Clients successfully entered the fake SSID to the internet.

    Please explain to me why clients can access the internet and how to prevent APs on the device system.

    I can go to the site to detect the signal through the analyzer software, but I live quite far away and there are many sites.

     I really want advice, thank you very much.





  • 2.  RE: Prevent AP from plugging into LAN

    EMPLOYEE
    Posted 29 days ago

    Depending on the Cisco Switch Type (supported Device or not) you can put it as monitored Device into AirWave. Than you will get the Switch Port Information in the Rogue dashboard / Report.




  • 3.  RE: Prevent AP from plugging into LAN

    Posted 29 days ago

    Thank you,

    The wan port of the Wifi Router (AP Rogue) has been cloned to the MAC, so how can you detect the AP Rogue?




  • 4.  RE: Prevent AP from plugging into LAN

    Posted 29 days ago

    Hi

    If you list all the client MAC addresses on the switch, can you eliminate all legit MAC addresses and find the MAC address of the Rouge AP?

    Do you have any form of authentication on the switch ports?



    ------------------------------
    Best Regards
    Jonas Hammarbäck
    MVP Guru 2024, ACEX, ACDX #1600, ACCX #1335, ACX-Network Security, Aruba SME, ACMP, ACSA
    Aranya AB
    If you find my answer useful, consider giving kudos and/or mark as solution
    ------------------------------



  • 5.  RE: Prevent AP from plugging into LAN

    Posted 29 days ago

    Thank you,

    I manage quite a few branches and it is very difficult to control MAC Clients. The Rogue AP was cloned to the same MAC as the internal computer's MAC and was in wifi Router mode (NAT mode) so I couldn't actually find it on the system.




  • 6.  RE: Prevent AP from plugging into LAN

    EMPLOYEE
    Posted 29 days ago

    As Jonas stated, a future proof solution would be implementing 802.1X on ETH Ports. With ClearPass you can use factory default Certificates of that AP. 

    Or you use Username Password with EAP-PEAP. with any Radius Server.

    No one onsite who can have a look for that device?




  • 7.  RE: Prevent AP from plugging into LAN

    Posted 19 days ago

    Thanks for your suggestion, I found AP Rogue on on Switch under Airwave