Wireless Access

last person joined: yesterday 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Rogue containment

This thread has been viewed 21 times
  • 1.  Rogue containment

    Posted Feb 18, 2015 10:13 AM

    We are trying to test our rogue containment with airwave and can't seem to block the SSID. We have a phone being used as a hotspot. Airwave detects it, and I go into Airwave and set it's classification as a contained rogue. I also go into the controller and set it as contain manually, and marked to contain 'yes' - we do not have offloading turned on. I have wireless containment set to 'tarpit-non-valid-sta'. What am I missing here?

    Thanks,

    Russell



  • 2.  RE: Rogue containment

    Posted Feb 18, 2015 11:00 AM

    Hi,

     

    Did you configure the following in RAPIDS ?

     

    1. manage rogue containment set to yes?

    2. manage rogue ap containment in monitor only mode is also allowed ?

     

    As a good practice, remove " contain manually " in the controller coz, Airwave will send the instruction to the Controller if it finds a rouge .

     

    Please feel free for any further help on this.



  • 3.  RE: Rogue containment

    Posted Feb 18, 2015 11:29 AM

    both are set to yes.

     



  • 4.  RE: Rogue containment

    Posted Feb 19, 2015 12:21 AM
    M


  • 5.  RE: Rogue containment

    Posted Feb 19, 2015 12:22 AM
    Be aware of local laws which may prevent this kind of setup.


  • 6.  RE: Rogue containment

    Posted Sep 28, 2016 10:45 AM

    How does the Controller treat a hotspot we mark to contain, if I manually contain it?

     

    Note:  We only use Airwave for reporting.. so I don't think Airwave will help us here.

     

    Does the Crontroller treat anything differently depending how it is labeled, if it is 'not' marked to contain?

    I.E. rogue vs suspected rogue vs Interfering vs Neighbor vs Valid



  • 7.  RE: Rogue containment

    EMPLOYEE
    Posted Sep 28, 2016 10:49 AM

    If you mark to contain, the controller will actively send out deauths whenever a device tries to associate to it.

    If it is just marked rogue, there are settings that say what the controller will do if it sees a rogue device.  It could just report it, or send out deauths.  Please see the guide here:  Aruba_WIP_Technology_Guide_v1.pdf ‏369 KB



  • 8.  RE: Rogue containment

    Posted Sep 28, 2016 11:02 AM

    The guide seems to approach it from the Airwave perspective.

     

    Where do I see these settings on the confroller?

    7240



  • 9.  RE: Rogue containment

    EMPLOYEE


  • 10.  RE: Rogue containment

    Posted Sep 28, 2016 12:37 PM

    When containing a rogue, how are the sorrounding valid SSID/users treated?  Are they left untouched, or will the de-auth affect them as well?