Detecting Rogue APs
The most importantWIP functionality is the ability to classify an AP as a potential security threat. AnA P is
considered to be a rogueA P if it is both unauthorized and pluggedinto the wired side of the network. An AP i s
considered to be an interferingAP i f it is seen in the RF environment but is not connected to the wired network.
Whilethe interfering AP can potentially cause RF interference,it is not considered a direct security threat since it is
not connected to the wired network. However, an interferingA P may be reclassified as a rogue AP.

Understand ing Classification Terminolo gy

APs and clients are discovered duringscanning of the wireless medium, and they are classified into various groups.
The AP and client classification definitions are in Table 103 and Table10 4.

Classification Description

Valid AP AnAP that is part of the enterprise providi ng WLAN service.
InterferingAP AnAP that is seen in the RF environment but is not connected to thew ired network. An
interferingAP isnot considered a direct security threat since it is not connected to the wi red
network.For example, aninterfering AP can be an AP that belongs to a neighboring office’s
WLANbut is not part of your W LANnetwork.
Neighbor AP A neighbori ng AP is when the BSSIDsare known. Once classified, a nei ghboring AP does not
changei tsstate.
RogueAP Anunauthorized AP that is plugged into the wired side of the network.
Suspected-RogueAP Asuspected rogue AP is an unauthorized AP that may be plugged into the wired side of the
network.
Manually-contained AP AnAP for which DoS i senabl ed manually.

Table10 3:

APC lassification Definition

Classification Description

Valid Client Any client that successfullyauthenticates with a valid AP and passes encrypted trafficis
classifiedas a validclient.
Manually-contained Client Anyclientsfor whi ch DoS is enabled manually.
InterferingCli ent Acli entassociated to any AP and is not valid.

Table10 4:

ClientClass ification Definitions

Understand ing Classification Methodo logy

A discovered AP is classified as a rogue or a suspected rogue by the followingmethods:
lInternalheuristics
lAP classification rules
lManuallyby the user
The internalheuristics worksby checkingif t he discovered AP is communicating wit h a wired device on the
customer network.This i s doneby matchingt heMA C addressof devices t hat areon the disco veredAP ’s network
DellPowerConnect W- Series ArubaOS 6.2 | UserGuide WirelessIntrusionPr evention |368