malicious rogue vs. rogue?
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-09-2017 03:05 PM
Been googling a bit, but I'm not finding what the difference is between a "rogue AP" (I get that) and a "malicious rogue AP". Also the logging is odd - I get log events of the rogue AP going away, but no mention of it appearing. Log example:
That MAC belongs to a Netgear device, so I'm assuming it's some consumer router. It would be helpful if an SSID was logged as well...
2017/03/09 14:15:09 | High | A Malicious Rogue[40:5d:82:12:5d:93] detection by AP[1c:b9:c4:35:eb:e0] goes away
7 REPLIES 7
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-17-2018 10:24 AM
I'd still like an answer to this. 🙂
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-17-2018 10:37 AM
Also I don't know why this doesn't trigger an email alert. I tested that alerts work (see screenshot). And you can see the checkbox is checked. This is a ZD on latest 10.x.

Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-16-2018 01:13 PM
Bump! I can open a case if necessary.
It's a pain to get notified of complaints, then login to the ZD, check the logs, see the rogue is there, and then wonder why I have no email telling me about this. Makes us look sloppy, we're trying to be proactive. The test works correctly and we see the test email. The test email is fine, whitelisted. Looking in spam box there's no evidence of these alerts.
It's a pain to get notified of complaints, then login to the ZD, check the logs, see the rogue is there, and then wonder why I have no email telling me about this. Makes us look sloppy, we're trying to be proactive. The test works correctly and we see the test email. The test email is fine, whitelisted. Looking in spam box there's no evidence of these alerts.

