5-98
Cisco Wireless LAN Controller Configuration Guide
OL-17037-01
Chapter 5 Configuring Security Solutions
Managing Rogue Devices
This page shows the MAC addresses of any access points that are configured to be ignored. The
rogue-ignore list contains a list of any autonomous access points that have been manually added to WCS
maps by WCS users. The controller regards these autonomous access points as rogues even though WCS
is managing them. The rogue-ignore list allows the controller to ignore these access points. The list is
updated as follows:
•
When the controller receives a rogue report, it checks to see if the unknown access point is in the
rogue-ignore access point list.
•
If the unknown access point is in the rogue-ignore list, the controller ignores this access point and
continues to process other rogue access points.
•
If the unknown access point is not in the rogue-ignore list, the controller sends a trap to WCS. If
WCS finds this access point in its autonomous access point list, WCS sends a command to the
controller to add this access point to the rogue-ignore list. This access point is then ignored in future
rogue reports.
•
If a user removes an autonomous access point from WCS, WCS sends a command to the controller
to remove this access point from the rogue-ignore list.
Using the CLI to View and Classify Rogue Devices
Using the controller CLI, enter these commands to view and classify rogue devices.
1.
To view a list of all rogue access points detected by the controller, enter this command:
show rogue ap summary
Information similar to the following appears:
Rogue Location Discovery Protocol................ Enabled
Rogue AP timeout................................. 1200
MAC Address Classification # APs # Clients Last Heard
----------------- ------------------ ----- --------- -----------------------
00:0a:b8:7f:08:c0 Friendly 0 0 Not Heard
00:0b:85:01:30:3f Malicious 1 0 Fri Nov 30 11:30:59 2007
00:0b:85:63:70:6f Malicious 1 0 Fri Nov 30 11:20:14 2007
00:0b:85:63:cd:bf Malicious 1
0
Fri Nov 30 11:23:12 2007
...
2.
To view a list of the friendly rogue access points detected by the controller, enter this command:
show rogue ap friendly summary
Information similar to the following appears:
Number of APs.................................... 1
MAC Address State # APs # Clients Last Heard
----------------- ------------------ ----- --------- ---------------------------
00:0a:b8:7f:08:c0 Internal 1 0 Tue Nov 27 13:52:04 2007