Provides an overview of rogue Protected Management Frame (PMF) concepts, configuration tasks, and verification references for wireless security management.
Rogue PMF containment is a wireless security feature that
-
uses 802.11w Protected Management Frames (PMF) to contain rogue APs and clients
-
operates on centrally switched WLANs when the radio channel of the detecting AP matches the rogue AP's channel, and
-
activates only when certain mode and channel conditions are met to secure the network against unauthorized devices.
Feature history
| Feature name |
Release information |
Feature description |
|---|---|---|
| Rogue PMF containment |
Cisco IOS XE 17.12.1 |
Starting with Cisco IOS XE Dublin 17.12.1, the controller contains a rogue AP with 802.11w Protected Management Frame (PMF) on centrally switched wireless LANs. Containment occurs if the client-serving radio channel of a rogue-detecting AP matches the channel of the corresponding rogue AP. |
Operational scenarios
PMF containment occurs in these scenarios:
-
You can use PMF containment only in the local mode.
-
You can perform PMF containment only for rogue clients that have not joined a rogue AP.
-
You can use PMF containment only if a rogue-detecting AP shares the same primary channel with a rogue client.
-
You cannot use PMF containment on DFS channels, even if a DFS channel serves as the client-serving channel.
-
PMF containment works only if at least one WLAN operates on the serving radio.
For information about APs that support the Rogue PMF Containment feature, see Cisco AP Feature Matrix.