Overview
Details procedures for containing rogue APs on both wired and wireless network infrastructures.
Rogue AP Containment overview
Introduces the Rogue AP Containment feature in Catalyst Center, which mitigates security threats by disabling wired switchports or initiating wireless deauthentication. This overview covers wired and wireless containment methods, auto-containment capabilities, and supported Cisco controller models for effective rogue device management.
Wired rogue AP containment
Details the Wired Rogue AP Containment feature, which allows administrators to shut down ACCESS mode switchports where rogue APs are physically connected. Explains the procedure for initiating containment via the Threat 360 window, reviewing configuration previews, and monitoring the status of the switchport shutdown process.
Wireless Rogue AP Containment
Explains the Wireless Rogue AP Containment feature in Catalyst Center, which disrupts communication between rogue APs and clients. Details the procedures for starting and stopping containment, monitoring status levels, and understanding operational limitations such as resource constraints, PMF, and DFS channel impacts.
Cisco Rogue AP Containment Actions Compatibility Matrix
Details the Cisco Rogue AP Containment Actions Compatibility Matrix, which outlines the availability of specific containment actions—such as Start, Stop, and Shutdown Switchport—based on the rogue AP's threat type and its current containment status within the network.
View tasks and audit logs of rogue AP containment type
Provides instructions for viewing tasks and audit logs related to wired and wireless rogue AP containment in Catalyst Center. Details how to filter activities by the ROGUE category and explains the differences in log formats between Cisco AireOS CLI commands and Cisco Catalyst 9800 Series Wireless Controller NETCONF requests.