Introduces rogue device concepts, covering detection techniques, containment strategies, integration with Cisco Prime Infrastructure, MFP-based and off-channel PMF containment, AP impersonation detection, security level configuration, management frame protection, policy configuration, and provides verification procedures for comprehensive rogue threat management.
A rogue device is any unauthorized network device.
A rogue device can:
-
disrupt wireless LAN operations by hijacking legitimate clients,
-
facilitate attacks such as plaintext, denial-of-service, and man-in-the-middle attacks on wireless networks, and
-
pose serious security risks by allowing unauthorized access, interception, and breaches inside the corporate firewall.
Risks and impact on network security
Rogue access points are a common form of rogue devices. Hackers can use rogue access points to capture sensitive information such as usernames and passwords. By transmitting a series of Clear to Send (CTS) frames, a rogue access point can mimic a legitimate access point. This action instructs a specific client to transmit while forcing other clients to wait, which prevents legitimate clients from accessing network resources.
Ban rogue access points from the air space to protect users and maintain network integrity.
Because rogue access points are inexpensive and available, staff may connect unauthorized access points to existing LANs. This can create ad hoc wireless networks without approval from IT departments.
These rogue access points can create serious security risks because they may connect inside the corporate firewall. If security settings are disabled on these devices, unauthorized users can intercept network traffic and hijack client sessions. When wireless users connect to rogue access points within the enterprise network, the risk of a security breach increases.
Rogue client status change
The controller marks the rogue client as a threat if a wireless client in the RUN state has the same MAC address.