Download Print this page

Rogue Ap Detection - Extreme Networks Summit WM3000 Series Reference Manual

Summit wm3000 series controller system software version 4.0

Advertisement

Rogue AP Detection

The controller supports the following techniques for rogue AP detection:
RF scan by Access Point on all channels
SNMP Trap on discovery
Authorized AP Lists
Rogue AP Report
Extreme Networks WMS Support
NOTE
The Extreme Networks Wireless LAN Controller Management Software (WMS) is recommended to plan the
deployment of the controller. Extreme Networks WMS can help optimize the positioning and configuration of a
controller in respect to a WLAN's MU throughput requirements and can help detect rogue devices. For more
information, refer to the Extreme Networks documentation website at:
http://www.extremenetworks.com/go/documentation.
RF scan by Access Point on one channel
This process requires an Access Point to assist in Rogue AP detection. It functions as follows:
The controller sends a new configuration message to the adopted AP informing it to detect Rogue
APs.
The Access Point listens for beacons on its present channel.
It passes the beacons to the controller as it receives them without any modification.
The controller processes these beacon messages to generate the list of APs
This process of detecting a Rogue AP is non-disruptive and none of the MUs are disassociated during
this process. The Access Point will only scan on its present channel.
By choosing this option for detection, all capable Access Points will be polled for getting the
information.
RF scan by Access Point on all channels
The process used to scan for Rogue APs on all available channels functions as follows:
The controller sends a configuration message (with the Automatic Channel Selection (ACS) bit set
and channel dwell time) to the Access Point.
An Access Point starts scanning each channel and passes the beacons it hears on each channel to the
controller.
An Access Point resets itself after scanning all channels.
An controller then processes this information
SNMP Trap on discovery
An SNMP trap is sent for each detected and Rogue AP. Rogue APs are only detected, and notification is
provided via a SNMP trap.
NOTE
Wired side scanning for Rogue APs using WNMP is not supported. Similarly, Radius lookup for approved AP is not
provided.
Summit WM3000 Series Controller System Reference Guide
31

Hide quick links:

Advertisement

loading

This manual is also suitable for:

Summit wm3600Summit wm3700