Skip to main content (Press Enter).
Register | Sign in
Skip auxiliary navigation (Press Enter).
Skip main navigation (Press Enter).
Toggle navigation
Discussion
Support
Aruba Documentation Portal
Aruba Support Knowledge Base
Community Learning
News
ACEX Hall of Fame
MVP Overview
Tech Corners
Search
View Entry
Controller Based WLANs
View Only
Community Home
Library
2.7K
Members
13
last person joined: one year ago
APs, Controllers, VIA
Back to Library
How does Overlay Rogue AP Classification work?
0
Kudos
Jul 07, 2014 01:25 AM
vikrams@aruba
Overlay Rogue AP Classification option can be used to reduce false positives when detecting Rogue APs.
It is possible that Aruba AP/AM can mark an AP as Rogue if it does not see all the frames for a station but does see some frames that are relayed on behalf of the station. Internal mechanism to what causes this issue is out of scope of the article.
If "Overlay Rogue AP Classification" is enabled, AP/AM will use the wired-MAC addresses that Aruba AP/AM collect on the air for Valid/Rogue APs, as addresses of devices on the trusted network. We will then use these addresses to compare against wired-MAC addresses that are collected on the air for an interfering AP, to detect a rogue. If there is a match we will mark AP as rogue as a Match-Type of "AP Wired MAC".
If "Overlay Rogue AP Classification" is disabled, then we will not use these MAC addresses for detecting AP as Rogue. We will only use wired-MAC addresses that are collected on the Aruba AP's Ethernet interface to detect a rogue. This means that the Match-Type of "AP-Wired-MAC" will not be triggered.
In 3.x onwards this option is part of 'ids unauthorized device profile'. In 2.5.4.x onwards it can be configured using command 'wms ap-policy overlay-classification <enable / disable>.
Statistics
0 Favorited
1 Views
0 Files
0 Shares
0 Downloads
Related Entries and Links
No Related Resource entered.
Privacy policy
Terms of service
Site Map
Legal
© Copyright 2024 Hewlett Packard Enterprise Development LP
All Rights Reserved.
Powered by Higher Logic