Wireless Access

last person joined: yesterday 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Send Alert When a Rogue AP is Connected to the LAN

This thread has been viewed 6 times
  • 1.  Send Alert When a Rogue AP is Connected to the LAN

    Posted Jan 11, 2013 09:32 AM

    I'd like to get an alert when a Rogue AP is classified as "Detected Wirelessly and on LAN". I thought about creating a trigger for it, but it isn't obvious to me how to configure it for this. How would you do this?

    Thanks,
    Robert

     



  • 2.  RE: Send Alert When a Rogue AP is Connected to the LAN

    Posted Jan 11, 2013 09:57 AM

    You might check the "Setting Triggers for IDS Events" on Airwave User Guide ( its in page 211 on Airwave 7.5 UG).

     

    Goodluck!



  • 3.  RE: Send Alert When a Rogue AP is Connected to the LAN

    Posted Jan 11, 2013 11:06 AM

    Thanks. I'd looked over that. The rules under RAPIDS all have a threat level of 5. I bumped the rule for Rogues on the LAN to threat level 6 and made a trigger based off the threat level. I'll see how that works.



  • 4.  RE: Send Alert When a Rogue AP is Connected to the LAN

    Posted Jan 11, 2013 02:59 PM

    It looks like another option would be to create a report that runs regularly with the option "New Rogue Devices: Devices Discovered on the LAN Only" reported. I'll try that too.

     

    Robert

     



  • 5.  RE: Send Alert When a Rogue AP is Connected to the LAN

    Posted Jan 14, 2013 02:59 PM

    I know that you can setup an email alert...I am seeking to be able to generate/send via syslog or SNMP Trap.  Any information would be appreciated.



  • 6.  RE: Send Alert When a Rogue AP is Connected to the LAN

    EMPLOYEE
    Posted Jan 14, 2013 05:23 PM

    @hartwell.watkins wrote:

    I know that you can setup an email alert...I am seeking to be able to generate/send via syslog or SNMP Trap.  Any information would be appreciated.


    The controller will do that by default (send SNMP traps and syslog).  In Airwave you can also forward to an NMS in a trigger.