Cisco 2100 Series Configuration Manual page 271

Wireless lan controller
Hide thumbs Also See for 2100 Series:
Table of Contents

Advertisement

Chapter 5
Configuring Security Solutions
Table 5-8
Rule-Based Classification Type
Unclassified
If you upgrade to controller software release 5.0 or later, the classification and state of the rogue access
points are reconfigured as follows:
From Known to Friendly, Internal.
From Acknowledged to Friendly, External.
From Contained to Malicious, Contained.
As mentioned previously, the controller can automatically change the classification type and rogue state
of an unknown access point based on user-defined rules, or you can manually move the unknown access
point to a different classification type and rogue state.
and rogue states from and to which an unknown access point can be configured.
Table 5-9
From
Friendly (Internal, External, Alert)
Friendly (Internal, External, Alert)
Friendly (Alert)
Malicious (Alert, Threat)
Malicious (Contained, Contained Pending)
Unclassified (Alert, Threat)
Unclassified (Contained, Contained Pending)
Unclassified (Alert)
If the rogue state is Contained, you have to uncontain the rogue access point before you can change the
classification type. If you want to move a rogue access point from Malicious to Unclassified, you must
delete the access point and allow the controller to reclassify it.
OL-17037-01
Classification Mapping (continued)
Rogue States
Pending—On first detection, the unknown access point is put in
the Pending state for 3 minutes. During this time, the managed
access points determine if the unknown access point is a
neighbor access point.
Alert—The unknown access point is moved to Alert if it is not
in the neighbor list or in the user-configured friendly MAC list.
Contained—The unknown access point is contained.
Contained Pending—The unknown access point is marked
Contained, but the action is delayed due to unavailable
resources.
Allowable Classification Type and Rogue State Transitions
Table 5-9
shows the allowable classification types
To
Malicious (Alert)
Unclassified (Alert)
Friendly (Internal, External)
Friendly (Internal, External)
Malicious (Alert)
Friendly (Internal, External)
Unclassified (Alert)
Malicious (Alert)
Cisco Wireless LAN Controller Configuration Guide
Managing Rogue Devices
5-83

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

4400 series

Table of Contents