Cisco Cisco 5508 Wireless Controller Referencia técnica

Descargar
Página de 42
4
Rogue Management in a Unified Wireless Network using v7.4
Cisco CleanAir® technology is an effective tool to monitor and manage your network's RF conditions. 
Cisco MSE extends those capabilities. 
 provides a summary of CleanAir plus MSE offers.
Rogue Overview
Any device that shares your spectrum and is not managed by you can be considered a rogue. A rogue 
becomes dangerous in the following scenarios:
When the Rogue AP uses the same SSID as your network (honeypot).
When the Rougue AP device is detected on wired network also.
Ad-hoc rogues are also a big threat.
Setup by an outsider with malicious intent.
There are three main phases of rogue device management in Cisco Unified Wireless Network (UWN) 
solution:
Detection – Radio Resource Management (RRM) scanning is used to detect the presence of rogue 
devices.
Classification – Rogue Location Discovery Protocol (RLDP), Rogue Detectors and switch port 
tracing are used to identify if the rogue device is connected to the wired network. Rogue 
classification rules also assist in filtering rogues into specific categories based on their 
characteristics.
Mitigation – Switch port Trace and shutting down, rogue location, and rogue containment are used 
to track down physical location and nullify the threat of rogue devices.
Table 2
CleanAir plus MSE Offers
CleanAir 
Access 
Points-(2600, 
3500, 3600) 
plus WLC
CleanAir 
Access Points 
plus WLC 
plus MSE
Rogue mitigation
Yes
Yes
Detect, classify, and mitigate interferers
Yes
Yes
Maintain air quality
Yes
Yes
Detect Layer 1 exploits
Yes
Yes
Track and trace rogues
No
Yes
Security penetration and DoS attack 
mitigation
No
Yes
System wide interferer details and event 
correlation
No
Yes
Zone of impact and interferer notification No
Yes
Track and trace interferers and Layer 1 
exploits
No
Yes