Back in 7.4 or 7.5, we tested connecting a rougue AP in to our lab switch and Airwave correctly identified the rogue and sent our NMS and syslog an alert -- all good.
Today I've plugged in the rogue for a show-and-tell with our PCI assessor and Airwave had elected to declare the AP a "suspected neighbor"
Did something change in the underlying logic, or were a week of tests missing some crucial bit of testing?
Lab switch had point-of-sale and client and wireless VLANs trunked to iAP, connect a "rogue" (linksys) to point-of-sale port and connect power. the iAP almost immediately shows the rogue in the IDS page:
After a few minutes, I notice that I haven't received the e-mail from Airwave, nor from the NMS or Syslog.
I check Airwave and it thinks we have a neighbor:
What's missing? Or how do I trace Airwave's logic to see where I need to tune it?
My rules: