<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: malicious rogue vs. rogue? in Unleashed</title>
    <link>https://community.ruckuswireless.com/t5/Unleashed/malicious-rogue-vs-rogue/m-p/43569#M4308</link>
    <description>Yes, if you collect a wireless trace from an AP.&amp;nbsp; A "rogue" is defined as any device not managed by your controller.&lt;BR /&gt;Malicious is if they are advertising our SSID, or DHCP.</description>
    <pubDate>Fri, 10 Mar 2017 00:39:07 GMT</pubDate>
    <dc:creator>michael_brado</dc:creator>
    <dc:date>2017-03-10T00:39:07Z</dc:date>
    <item>
      <title>malicious rogue vs. rogue?</title>
      <link>https://community.ruckuswireless.com/t5/Unleashed/malicious-rogue-vs-rogue/m-p/43566#M4305</link>
      <description>Been googling a bit, but I'm not finding what the difference is between a "rogue AP" (I get that) and a "malicious rogue AP". &amp;nbsp;Also the logging is odd - I get log events of the rogue AP going away, but no mention of it appearing. &amp;nbsp;Log example:&lt;BR /&gt;&lt;PRE&gt;&lt;BR /&gt;2017/03/09&amp;nbsp;&amp;nbsp;14:15:09 | High&amp;nbsp;| A Malicious Rogue[40:5d:82:12:5d:93] detection by AP[1c:b9:c4:35:eb:e0] goes away&lt;/PRE&gt;That MAC belongs to a Netgear device, so I'm assuming it's some consumer router. &amp;nbsp;It would be helpful if an SSID was logged as well...</description>
      <pubDate>Thu, 09 Mar 2017 23:05:41 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/Unleashed/malicious-rogue-vs-rogue/m-p/43566#M4305</guid>
      <dc:creator>charles_sprickm</dc:creator>
      <dc:date>2017-03-09T23:05:41Z</dc:date>
    </item>
    <item>
      <title>Re: malicious rogue vs. rogue?</title>
      <link>https://community.ruckuswireless.com/t5/Unleashed/malicious-rogue-vs-rogue/m-p/43567#M4306</link>
      <description>A rogue AP is any AP that your AP can hear the beacons from that is not part of your wifi network. Another vendors AP in the next office will show up as a rogue. Not usually a problem unless they are blasting your office too. Malicious AP is an AP that your AP can hear and its either transmitting your SSID (man in the middle attack) usually with an open SSID which clients may prefer and will connect to it instead of your AP. Or another scenario is when an AP that is not part of your wifi system and it is on your network. There are a couple of other types of malicious APs but they dont happen very often.&lt;BR /&gt;&lt;BR /&gt;Hope this helps</description>
      <pubDate>Thu, 09 Mar 2017 23:15:55 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/Unleashed/malicious-rogue-vs-rogue/m-p/43567#M4306</guid>
      <dc:creator>mike_kuly_hdvuk</dc:creator>
      <dc:date>2017-03-09T23:15:55Z</dc:date>
    </item>
    <item>
      <title>Re: malicious rogue vs. rogue?</title>
      <link>https://community.ruckuswireless.com/t5/Unleashed/malicious-rogue-vs-rogue/m-p/43568#M4307</link>
      <description>Is there any way to coax more logging out of the Ruckus? &amp;nbsp;I'd like to know if the malicious rogue AP is using the same SSID or not (as that would certainly explain a lot of problems). &amp;nbsp;Also, any idea on why only the "goes away" state is logged?</description>
      <pubDate>Thu, 09 Mar 2017 23:42:23 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/Unleashed/malicious-rogue-vs-rogue/m-p/43568#M4307</guid>
      <dc:creator>charles_sprickm</dc:creator>
      <dc:date>2017-03-09T23:42:23Z</dc:date>
    </item>
    <item>
      <title>Re: malicious rogue vs. rogue?</title>
      <link>https://community.ruckuswireless.com/t5/Unleashed/malicious-rogue-vs-rogue/m-p/43569#M4308</link>
      <description>Yes, if you collect a wireless trace from an AP.&amp;nbsp; A "rogue" is defined as any device not managed by your controller.&lt;BR /&gt;Malicious is if they are advertising our SSID, or DHCP.</description>
      <pubDate>Fri, 10 Mar 2017 00:39:07 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/Unleashed/malicious-rogue-vs-rogue/m-p/43569#M4308</guid>
      <dc:creator>michael_brado</dc:creator>
      <dc:date>2017-03-10T00:39:07Z</dc:date>
    </item>
    <item>
      <title>Re: malicious rogue vs. rogue?</title>
      <link>https://community.ruckuswireless.com/t5/Unleashed/malicious-rogue-vs-rogue/m-p/43570#M4309</link>
      <description>Can you clarify a bit more? &amp;nbsp;I get "advertising our SSID" I think - another AP in range with the same SSID. &amp;nbsp;Clearly bad. &amp;nbsp;I don't get the "or DHCP" part. &amp;nbsp;What does that mean? &amp;nbsp;How can my AP detect anything having to do with DHCP on an AP that's not on my network?&lt;BR /&gt;&lt;BR /&gt;Also in this message:&lt;BR /&gt;&lt;BR /&gt;A new Same-Network Rogue[f0:b0:52:37:cf:fc] with SSID[CableWiFi] is first detected by AP[RuckusAP 2@1c:b9:c4:35:eb:e0]&lt;BR /&gt;&lt;BR /&gt;What does "Network" refer to in the context of "same network"? &amp;nbsp;I assume not the same SSID, as the SSID is logged as the ubiquitous "CableWiFi". &amp;nbsp;Does network mean "channel" in this context?</description>
      <pubDate>Fri, 07 Apr 2017 02:16:25 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/Unleashed/malicious-rogue-vs-rogue/m-p/43570#M4309</guid>
      <dc:creator>charles_sprickm</dc:creator>
      <dc:date>2017-04-07T02:16:25Z</dc:date>
    </item>
    <item>
      <title>Re: malicious rogue vs. rogue?</title>
      <link>https://community.ruckuswireless.com/t5/Unleashed/malicious-rogue-vs-rogue/m-p/43571#M4310</link>
      <description>I'd still like an answer to this. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;</description>
      <pubDate>Tue, 17 Apr 2018 17:24:26 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/Unleashed/malicious-rogue-vs-rogue/m-p/43571#M4310</guid>
      <dc:creator>erin_mcclellen</dc:creator>
      <dc:date>2018-04-17T17:24:26Z</dc:date>
    </item>
    <item>
      <title>Re: malicious rogue vs. rogue?</title>
      <link>https://community.ruckuswireless.com/t5/Unleashed/malicious-rogue-vs-rogue/m-p/43572#M4311</link>
      <description>Also I don't know why this doesn't trigger an email alert.&amp;nbsp; I tested that alerts work (see screenshot).&amp;nbsp; And you can see the checkbox is checked.&amp;nbsp; This is a ZD on latest 10.x.&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="Image_ images_messages_5f91c46e135b77e247a81f61_2102165a32275493004b5ad2c360551c_RackMultipart20180417389999op9-19650c53-1a70-4f9a-9411-3ef202568a0a-1709490274.png1523986579"&gt;&lt;img src="https://community.ruckuswireless.com/t5/image/serverpage/image-id/1013i2EDDCE628731B333/image-size/large?v=v2&amp;amp;px=999" role="button" title="Image_ images_messages_5f91c46e135b77e247a81f61_2102165a32275493004b5ad2c360551c_RackMultipart20180417389999op9-19650c53-1a70-4f9a-9411-3ef202568a0a-1709490274.png1523986579" alt="Image_ images_messages_5f91c46e135b77e247a81f61_2102165a32275493004b5ad2c360551c_RackMultipart20180417389999op9-19650c53-1a70-4f9a-9411-3ef202568a0a-1709490274.png1523986579" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="Image_ images_messages_5f91c46e135b77e247a81f61_df028936bd3439fcba6bc36245dd24bc_RackMultipart2018041730174b6er-d108c373-7c3f-42a2-a1a3-58118d3278c1-1636714103.png1523986621"&gt;&lt;img src="https://community.ruckuswireless.com/t5/image/serverpage/image-id/1014iCF3EC39E80E77F3D/image-size/large?v=v2&amp;amp;px=999" role="button" title="Image_ images_messages_5f91c46e135b77e247a81f61_df028936bd3439fcba6bc36245dd24bc_RackMultipart2018041730174b6er-d108c373-7c3f-42a2-a1a3-58118d3278c1-1636714103.png1523986621" alt="Image_ images_messages_5f91c46e135b77e247a81f61_df028936bd3439fcba6bc36245dd24bc_RackMultipart2018041730174b6er-d108c373-7c3f-42a2-a1a3-58118d3278c1-1636714103.png1523986621" /&gt;&lt;/span&gt;</description>
      <pubDate>Tue, 17 Apr 2018 17:37:11 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/Unleashed/malicious-rogue-vs-rogue/m-p/43572#M4311</guid>
      <dc:creator>erin_mcclellen</dc:creator>
      <dc:date>2018-04-17T17:37:11Z</dc:date>
    </item>
    <item>
      <title>Re: malicious rogue vs. rogue?</title>
      <link>https://community.ruckuswireless.com/t5/Unleashed/malicious-rogue-vs-rogue/m-p/43573#M4312</link>
      <description>Bump!&amp;nbsp; I can open a case if necessary.&lt;BR /&gt;&lt;BR /&gt;It's a pain to get notified of complaints, then login to the ZD, check the logs, see the rogue is there, and then wonder why I have no email telling me about this.&amp;nbsp; Makes us look sloppy, we're trying to be proactive. The test works correctly and we see the test email. The test email is fine, whitelisted.&amp;nbsp; Looking in spam box there's no evidence of these alerts.</description>
      <pubDate>Wed, 16 May 2018 20:13:05 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/Unleashed/malicious-rogue-vs-rogue/m-p/43573#M4312</guid>
      <dc:creator>erin_mcclellen</dc:creator>
      <dc:date>2018-05-16T20:13:05Z</dc:date>
    </item>
  </channel>
</rss>

