Rogue Access Points

A "rogue access point" is any access point detected by an RUCKUS Unleashed access point that is not part of the RUCKUS Unleashed network. Rogue devices are detected during off-channel scans (background scanning) and are other access points that are not part of the RUCKUS Unleashed network (for example, an access point at a nearby coffee shop, a neighboring apartment or shopping mall).

Typically, rogue access points are not a threat, however there are certain types that do pose a threat that will be automatically identified as "malicious rogue APs." The automatically identified malicious rogue APs fall into the following three categories:

  • WLAN-Spoofing: Rogue APs that are beaconing the same WLAN name as a RUCKUS Unleashed access point. They pose a threat because someone may be attempting to use them as a "honeypot" to attract your clients into their network to attempt hacking or man-in-the-middle attacks to exploit passwords and other sensitive data.
  • Same-Network: Rogue APs that are detected by other access points to be transmitting traffic on your internal network. They are detected by RUCKUS Unleashed access points seeing packets coming from a "similar" MAC address to one of those detected from an over-the-air rogue AP. Similar MAC addresses are +-5 MAC addresses lower or higher than the detected over-the-air MAC address.
  • MAC-spoofing: Rogue APs that are beaconing the same MAC address as a RUCKUS Unleashed access point. They pose a threat because someone may be attempting to use them as a "honeypot" to attract your clients into their network to attempt hacking or man-in-the-middle attacks to exploit passwords and other sensitive data.