Wireless Access

last person joined: 16 hours ago 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

rogue AP removal

This thread has been viewed 9 times
  • 1.  rogue AP removal

    Posted Sep 25, 2020 12:24 PM
    We're going through a SOC2 audit and the auditors are asking several questions about our rogue AP settings and and configurations. We are running Aruba 315 APs, 8.6.0.4_74969, on Aruba Central.
    1. Rogue Access points Discovered During the Audit Period + Report Configurations/Parameters
    2. For a selection of rogue access points detection events, please provide ticket documentation noting that the event has been resolved appropriately by removing the rogue access point.
    1 is an easy answer but 2 I'm not sure how or what to answer. I don't see any provision to actually remove a rogue, just protect from it. There is containment but that's risky because we don't want to shut down our neighbors wireless network. Is there a misunderstanding on how Rogue detection/protection works on my or their part? I'm not a network admin and don't really have the chops for this but I'm the closest thing our shop has to one so any advice on this would be greatly appreciated.


  • 2.  RE: rogue AP removal

    Posted Sep 27, 2020 09:49 PM

    I don't believe I have the answers for you, but I will make a few comments that might help you understand some of this a little better. First off, there are different types of APs that a can show up. Of course you have your own APs which are running your network. A rogue AP is officially an AP that is plugged into your network, but you do not manage it or support it (somebody else plugged it in). An interfering AP is another other AP the your network hears, and is not plugged into your network; so neighbor APs, or personal phones or hotspots are all interfering. You can't do anything with interfering AP, they have as much right to use the RF and advertise their networks as you have to advertise your networks.

     

    In most countries around the world, it is illegal to generate wireless signals to disconnect somebody from a network or to jam or interfere with RF signals. Therefore, containment methods such as deauthentication or tarpitting are most likely illegal. Wired containment methods are legal since they do not violate RF regulations.

     

    Looking at your items, I'm interpreting them (and I may be wrong) that item 1 is looking for discovery and reporting of information about any rogues that are found. Item 2 appears to be requesting documentation that you located the rogue and physically removed it from the network. At least that is how I am reading those requests.

     



  • 3.  RE: rogue AP removal

    Posted Sep 28, 2020 08:39 AM

    Thank you for the reply. This is showing on Central. The question is are clients prevented from connecting to this? I would assume so as it has been identified.

    Screen Shot 2020-09-28 at 5.23.24 AM.png



  • 4.  RE: rogue AP removal

    Posted Sep 28, 2020 09:37 AM

    This is just identifying that this is a Rogue. Clients cannot be prevented from connecting. The Rogue needs to be manually/physically removed.

     



  • 5.  RE: rogue AP removal

    Posted Sep 28, 2020 11:27 AM

    Thanks for the help. The rogue ap was a wifi printer at the reception desk.



  • 6.  RE: rogue AP removal

    Posted Sep 28, 2020 11:32 AM

    I noticed. You should go to it and turn off the Wi-Fi adapter on it if it is not being used. If is using up unnecessary RF by advertising its SSID. It can also be a potential security risk.



  • 7.  RE: rogue AP removal

    Posted Sep 28, 2020 01:13 PM

    What's puzzling to me is that I didn't get any alerts when the printer came online. I removed all the filters on the alert so hopefully it will alert me next time. These are the current settings. Previously I had Group, Label, and Site defined....maybe that filtered out the alert?

    Screen Shot 2020-09-28 at 10.05.20 AM.png



  • 8.  RE: rogue AP removal

    Posted Sep 29, 2020 12:43 PM

    I'm still trying to figure out why I'm not being alerted when a rogue ap is detected. I turned on the printer that was being detected as a rogue and it turns up as a rogue in Security > Rapids > Rogues but I never get an alert that a rogue has been detected. I do have an alert set up for rogue detection, there is a screenshot of the settings in the previous post. I left all the filters blank in the settings and set to alert on Major or higher and received no alerts. I also tried setting the alert to Warning but still no alerts. What else can I check/change to get an alert on detection?



  • 9.  RE: rogue AP removal

    Posted Sep 29, 2020 04:23 PM

    looking at the documentation:

    "Rogue AP Detected—Generates an alert when a rogue Instant AP is detected. This alert is enabled by default and the alert severity is Major."

    Will it only alert on a rogue Instant AP and not a non instant ap, such as a printer for instance?