How do Aruba Air Monitor and Access Point compare?

Aruba Employee
Aruba Employee

Product and Software: This article applies to Aruba Air Monitor and Access Point.

The physical hardware of an Air Monitor (AM) is identical to that of an Access Point (AP). All APs can be set to operate in AM mode with a simple change of configuration.

Air Monitor

Clients cannot connect to an AM. The function of an AM is similar to a radio scanner because it analyzes all channels and detects all wireless attacks. An AM automatically classifies clients and APs as one of the three categories: valid, interfering, or rogue. An AM provides wireless protection without any reduction in valid client performance. An AM also scans other channels while disabling rogue clients. It also provides faster update speed for triangulation and centralized management of all events and alerts. An AM also is capable of remote packet capture on ANY channel in your regulatory domain AP and band(s).

Access Point

An AP is required to provide WiFi connectivity to clients: 802.11a, b/g, or latest N, depending on hardware. An Aruba AP can simultaneously support client connectivity and Wireless Intrusion Detection and Protection on the channel the AP is set to when the Adaptive Radio Management (ARM) feature and scanning is enabled.

Since rogue APs are detected by monitoring management frames in an AP or AM, a network with proper coverage design can have an excellent chance of detecting all rogues on the channels being used. When Wireless Intrusion Protection and ARM are enabled, if no clients are connected to the AP, the AP automatically allocates itself the same channel as the rogue AP and protects the network at the same time as it advertises service on the new channel. When ARM and scanning is enabled, an AP automatically classifies clients and APs as one of the three categories: valid, interfering, or rogue. It also provides triangulation of all clients and centralized management of all events and alerts. An AP also supports Remote Packet Capture on the channel that the AP is serving clients on.

Version history
Revision #:
1 of 1
Last update:
‎07-06-2014 08:50 AM
Updated by:
Labels (1)

It woud be better, if we involve spectrum monitor on this comparison.


With regards,


Fakir Mohideen.P



I have read the following in a guide:

"For the best rogue detection and to provide wired containment, the AM must be on the same VLAN as the rogue AP. If the network has multiple VLANs to which a rogue AP might connect, you should extend each of them to the AMs. "


Does this mean that when I provision an AM, I have to have all useable vlans tagged on the uplink port of the AM? After tagging all the vlans on uplink port of AM I assume I have to set the managemnet vlan (the vlan I have the dhcp option 43 set) of the AM in the IP settings (IP settings->Uplink Vlan)?

Is this correct? Or is there a recommended deployment for AM if I want to do wireless and wired containment?


Thanks in advance!



Search Airheads
Showing results for 
Search instead for 
Did you mean: