Viewing Rogue Devices

Rogue client page - 5.1.2 (FIPS/NonFIPS) update

A rogue device is any unauthorized device that connects to a network without explicit permission. These devices can be rogue access points or rogue clients, which can potentially compromise network security by providing unauthorized access to sensitive data or by disrupting network operations.

Rogue devices can be introduced intentionally by malicious actors or unintentionally by users who are unaware of the security implications. Regardless of their origin, it is crucial to detect and mitigate the risks associated with these devices.

In the main menu, navigate to Monitor > Report > Rogue Devices. In the Rogue Devices page, in the upper right corner, select Access Point or Client from the drop-down list.

Note: Enable Rogue AP detection in the Advanced Settings of the AP Zone. The device list is empty, if this setting is disabled.

The Rogue Devices page displays all the rogue APs or rogue clients that the controller has detected on the network, including the following information:

  • Rogue MAC: The MAC address of the rogue AP.
  • Type: The client has a different set of rogue types (for example, rogue, normal rogue AP, not yet categorized as malicious or non-malicious).
  • Classification Policy: The rogue classification policy associated with the rogue AP.
  • Channel: The radio channel used by the rogue AP.
  • Radio: The WLAN standards with which the rogue AP complies.
  • SSID: The WLAN name that the rogue AP is broadcasting.
  • Detecting AP Name: The name of the AP.
  • Zone: The zone to which the AP belongs.
  • RSSI: The radio signal strength.
  • Encryption: Indicates whether the wireless signal is encrypted.
  • Detected Time: The date and time that the rogue AP was last detected by the controller.