Cisco Catalyst Center Rogue Management and aWIPS Application Quick Start Guide, Release 3.1.x

PDF

Edit a rogue rule

Want to summarize with AI?

Log in

Overview

For a rogue AP with wireless containment status as Partial, an i icon appears adjacent to Partial state under the Containment column in the Threat 360 window. Hover your cursor over the i icon to view the current wireless containment status of the Rogue SSIDs.

Procedure

1.

From the main menu, choose Assurance > Rogue and aWIPS > Rules.

2.

In the Rogue Rules table, click the rule name that you want to edit.

3.

In the Edit Rogue Rule window, make changes as needed.

Note

The previous classification remains unchanged, even if old rules are used to modify the rule conditions. The change affects only the new data classification.

4.

(Optional) Check the Enable Auto-Containment check box to check box to enable automatic containment of the rogue rule.

Note
  • Cisco Catalyst 9800 Series Wireless Controllers have a limit of 625 configurations for rogue containment at a time. When the limit is reached, containment won't work for any new rogue on those devices.

  • You can only enable automatic containment for Honeypot and the custom rule with the High level threat.

  • If you want to disable automatic containment after it has been enabled, you must do so manually. Disabling automatically is not supported.

5.

Click Save.

Verify whether the rogue containment is enabled or not in the Auto-Containment column.