User Guide

Command Line Interface
7-110
7
rogue-ap enable
This command enables the periodic detection of nearby access points. Use the no
form to disable periodic detection.
Syntax
[no] rogue-ap enable
Default Setting
Disabled
Command Mode
Interface Configuration (Wireless)
Command Usage
While the access point scans a channel for rogue APs, wireless clients will
not be able to connect to the access point. Therefore, avoid frequent
scanning or scans of a long duration unless there is a reason to believe that
more intensive scanning is required to find a rogue AP.
A “rogue AP” is either an access point that is not authorized to participate
in the wireless network, or an access point that does not have the correct
security configuration. Rogue access points can be identified by unknown
BSSID (MAC address) or SSID configuration. A database of nearby access
points should therefore be maintained on a RADIUS server, allowing any
rogue APs to be identified (see “rogue-ap authenticate” on page 7-112).
The rogue AP database can be viewed using the show rogue-ap
command.
The access point sends Syslog messages for each detected access point
during a rogue AP scan.