
168 | Using RAPIDS and Rogue Classification Dell PowerConnect W AirWave 7.2 | User Guide
Filtered rogues are dropped from the system before they are processed through the rules engine. This can speed
up overall performance but will eliminate all visibility into these types of devices.
Rogue Containment Options
Using RAPIDS, AMP can shield rogue devices from associating to Cisco WLC controllers (versions 4.2.114 and
later), and Dell PowerConnect W controllers (running AOS versions 3.x and later). AMP will alert you to the
appearance of the rogue device and identify any mismatch between controller configuration and the desired
configuration.
Table 96 shows the Containment Options section of the RAPIDS > Setup page.
Table 94 RAPIDS > Setup > Classification Options Fields
Field Default Description
Acknowledge Rogues by
Default
No Sets RAPIDS to acknowledge rogue devices upon initial detection, prior to their
classification.
Manually Classifying
Rogues Automatically
Acknowledges them
Yes Defines whether acknowledgement happens automatically whenever a rogue device
receives a manual classification.
Table 95 RAPIDS > Setup > Filtering Options
Field Default Description
Filter Ad-hoc rogues No Filters rogues according to ad-hoc status.
Filter Rogues by Signal
Strength
No Filters rogues according to signal strength. Since anything below the established
threshold will be ignored and possibly dangerous, we do not recommend enabling this
setting. Instead, we recommend you incorporate signal strength into the classification
rules on the RAPIDS > Rules page.
Filter Rogues Discovered
by Remote APs
No Filters rogues according to the remote AP that discovers them. Enabling this option
causes AWMS to drop all rogue discovery information coming from remote APs.
Filter IDS Events from
Remote APs
No Filters IDS Events discovered by remote APs.
NOTE: WMS Offload is not required to manage containment in AMP.
Table 96 RAPIDS > Setup > Containment Options Fields and Default Values
Field Default Description
Manage rogue AP
Containment
Yes Rogue APs on Cisco WLC and Dell PowerConnect W controllers as defined by the Rules
engine will be classified as a Contained Rogue. AMP pushes the containment status of a
rogue device to the controller and the controller takes the appropriate action. For the
rogue device to be contained, you may need to configure containment on the controller.
Manage rogue AP
containment in monitor-
only mode
No If disabled, AMP will display the desired containment settings but will not push them to
devices. This may result in mismatches in device classifications. This can be useful for
administrators that want to see what RAPIDS would push to the controller without
making any changes to their network.
If enabled, AMP will push the desired containment settings to the controllers in Monitor-
Only mode, as well as the devices in Managed mode.
Maximum number of APs
to contain a rogue
3 Sets the maximum number of APs that will contain a rogue on Cisco WLC controllers.
Komentarze do niniejszej Instrukcji