Rogue AP Detection

Complete the following steps to enable or disable and configure rogue access point detection.

  1. From the main menu, select Security > WIPS > Intrusion Detection and Prevention.

    The WIPS paage is displayed.

  2. Select the Enable report rogue devices checkbox to include rogue device detection in logs and email alarm event notifications.
  3. Select which devices to include in rogue device reports:
    • Report all rogue devices: Send alerts for all rogue AP events.
    • Report only malicious rogue devices of type: Select which event types to report:
      • SSID-Spoofing: A malicious rogue AP that uses the same SSID as a RUCKUS Unleashed AP, also known as an "evil-twin" AP.
      • Same-Network: A malicious rogue AP that is connected to the same wired network.
      • MAC-Spoofing: A malicious rogue AP that has the same BSSID (MAC address) as one of the virtual APs managed by RUCKUS Unleashed.
      • User-Blocked: A rogue AP that has been marked as malicious by the user.
  4. Select the Protect the network from malicious rogue access points checkbox to automatically protect your network from network-connected rogue APs, WLAN-spoofing APs, and MAC-spoofing APs. When one of these rogue APs is detected (and this checkbox is enabled), the RUCKUS AP automatically begins sending broadcast de-authentication messages spoofing the rogue's BWLAN (MAC address) to prevent wireless clients from connecting to the malicious rogue AP. This option is disabled by default.
  5. Click Apply to save your changes.

    Intrusion Detection and Prevention