369| Wireless Intrusion Prevention DellPowerConnect W- Series ArubaOS 6.2 | User Guide
with that of the user’s wired network.The MAC of the device on the disco veredAP ’s networki s knownas t he

MatchMAC

. The ways in which the matching of wired MACs occurs is detailed in the sections "Understanding
Match Methods" on page 369 and "UnderstandingMatch Types" o n page3 69.
Understanding Match Methods
The match methods are:
lPlus One—Thematch MAC matches a device whose MAC address’ last bit was one more than that of the
Match MAC.
lMinus One—Thematch MAC matches a device whose MAC address’ last bit was one less than that of the
Match MAC.
lEqual—Thematch was against the same MAC address.
lOUI—Thematc hwas against the manufacturer’sOUI of the wired device.
The classification details are available in the ‘Discovered AP table’ section of t he‘Security Summary’ page of the
WebUI. The information can be obtained by clicking on the details icon for a selected discovered AP. The
information is also available in the command show wms rogue-ap.
Understanding Match Types
lEth-Wired-MAC—TheMAC addresses of wi reddevices learnedby an A P on its Ethernet interface.
lGW-Wired-MAC—Thecollection of Gateway MACs of all APs across the master and local Dell controllers.
lAP-Wired-MAC—TheMAC addresses of wired devices learnedby monit oringt raffico ut of other valid and rogue
APs.
lConfig-Wired-MAC—TheMAC addresses that are configuredby the user typically that of wellknown servers in
the network.
lManual—Usertriggered classification.
lExternal-Wired-MAC—TheMAC address matched a set of knownwired devices that are maintained in an
externaldatabase.
lMobility-Manager—Theclassification was determined by the mobility manager, AMP.
lClassification-off—AP is classified as rogue because classificati on has been disabled causing allnon-authorized
APs to be classified as a rogue.
lPropagated-Wired-MAC—TheMAC addresses of wired devices learned by a different AP than the one that uses
it for classifying a rogue.
lBase-BSSID-Override—Theclassification was derived fromanot herBSSID which belongs to the same AP that
supports multipleBSSIDs on the radio interface.
lAP-Rule—A user definedA P classification rule has matched.
lSystem-Wired-MAC—TheMAC addresses of wired devices learned at the controller.
lSystem-Gateway-MAC—TheGateway MAC addresses learnedat the controller.
Understanding Suspected Rogue Confidence Level
A suspected rogueAP is an AP that is potentially a threat to the WLAN infrastructure.A suspected rogue AP hasa
confidence levelassociat edwi th it. An AP can be marked as a suspected rogueif it is determined to be a potentially
threat on the wired network, or if it matches a user defined classification rule.
The suspected-rogueclassificatio n mechanismare:
lEach mechanism that causes a suspected-rogueclassification is as signeda confidence level increment of 20%.
lAP classification rules have a configured confidence level.