Wireless Access

last person joined: yesterday 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

RAPs vs RFP

This thread has been viewed 1 times
  • 1.  RAPs vs RFP

    Posted Feb 07, 2013 10:17 AM

    Hi All,

     

    Probably one for the security junkies here. Been a while since I saw a customer buy a WIP(RFP) license!

     

    Consider RAPs, and in this case, a customer has an RFP license obviously.

     

    My theory here is that I want RFP on the campus (configure that in detail later), but NOT on their RAPs. This is obviously because we want to avoid detecting rogues in user homes, ad-hocs in user homes etc. That's not really any of our business what they're doing! So as far as I can see, the best way to achieve this is by applying an unauthorized-device-profile into the ap-group, that has everything turned off, thus...

     

    ids unauthorized-device-profile "detection-disabled"
       no detect-windows-bridge
       no classification
       no overlay-classification
       no oui-classification
       no prop-wm-classification
       no detect-sta-assoc-to-rogue
       no detect-unencrypted-valid-client
       no detect-adhoc-using-valid-ssid
       no detect-valid-client-misassociation
    !

     

    Anybody care to suggest a flaw in this plan or thinking? Assume the corporate laptop at home is locked down by AD.

     

    Cheers!

     



  • 2.  RE: RAPs vs RFP

    Posted Feb 15, 2013 10:01 AM

    That would certainly work.

    We would still detect Wi-Fi networks as Interfering (except the Ad-Hoc of course).

     

    Good solution.

     

    Cheers

     

    Giles

     



  • 3.  RE: RAPs vs RFP

    Posted Mar 01, 2013 01:01 PM

    Have you got Airwave? If so, you can ignore Rogues from remote-aps.

     

    By disabling that profie, wouldn't it affect the ability to discover those IDS events at the campus level?


    Unless you have a specific AP group for Campus and 1 for RAPS at which point you can configure a IDS profile for the campus and do what you suggested for the RAP AP Group