Administrator Guide

Table Of Contents
537 | Wireless Intrusion Prevention Dell Networking W-Series ArubaOS 6.4.x| User Guide
Classification Description
Rogue AP An unauthorized AP that is plugged into the wired side of the network.
Suspected-Rogue AP A suspected rogue AP is an unauthorized AP that may be plugged into the wired
side of the network.
Manually-contained
AP
An AP for which DoS is enabled manually.
Classification Description
Valid Client Any client that successfully authenticates with a valid AP and passes encrypted
traffic is classified as a valid client.
Manually-contained
Client
Any clients for which DoS is enabled manually.
Interfering Client A client associated to any AP and is not valid.
Table 106: Client Classification Definitions
Understanding Classification Methodology
A discovered AP is classified as a rogue or a suspected rogue by the following methods:
l Internal heuristics
l AP classification rules
l Manually by the user
The internal heuristics works by checking if the discovered AP is communicating with a wired device on the
customer network. This is done by matching the MAC address of devices that are on the discovered AP’s
network with that of the users wired network. The MAC of the device on the discovered AP’s network is known
as the Match MAC. The ways in which the matching of wired MACs occurs is detailed in the sections
Understanding Match Methods on page 537 and Understanding Match Types on page 538.
Understanding Match Methods
The match methods are:
l Plus One—The match MAC matches a device whose MAC address last bit was one more than that of the
Match MAC.
l Minus OneThe match MAC matches a device whose MAC address last bit was one less than that of the
Match MAC.
l Equal—The match was against the same MAC address.
l OUI—The match was against the manufacturer’s OUI of the wired device.
The classification details are available in the ‘Discovered AP table section of the ‘Security Summary’ page of the
WebUI. The information can be obtained by clicking on the details icon for a selected discovered AP. The
information is also available in the command show wms rogue-ap.