CISCO-LWAPP-ROGUE-MIB
AI MIB Summary
The CISCO-LWAPP-ROGUE-MIB enables Cisco Central Controllers to monitor and manage rogue 802.11 Access Points and clients within the RF environment by exposing detection metrics, signal strength (RSSI), and Rogue Location Discovery Protocol (RLDP) status. This module facilitates the identification of unauthorized devices and the execution of containment actions for rogue APs and ad-hoc networks detected by LWAPP-enabled access points.
This MIB is intended to be implemented on all those devices operating as Central Controllers, that terminate the Light Weight Access Point Protocol tunnel from Cisco Light-weight LWAPP Access Points.
This MIB provides information about the Rogue APs and Clients that are detected by the controller.
The relationship between CC and the LWAPP APs can be depicted as follows:
+......+ +......+ +......+
+ + + + + +
+ CC + + CC + + CC +
+ + + + + +
+......+ +......+ +......+
.. . . .. . . . . . . . . . . . . . . . . . .
+......+ +......+ +......+ +......+
+ + + + + + + +
+ AP + + AP + + AP + + AP +
+ + + + + + + +
+......+ +......+ +......+ +......+
. . . . . . . . . . . . . . . . . . .
+......+ +......+ +......+ +......+
+ + + + + + + +
+ MN + + MN + + MN + + MN +
+ + + + + + + +
+......+ +......+ +......+ +......+
The LWAPP tunnel exists between the controller and the APs. The MNs communicate with the APs through the protocol defined by the 802.11 standard.
LWAPP APs, upon bootup, discover and join one of the controllers and the controller pushes the configuration, that includes the WLAN parameters, to the LWAPP APs. The APs then encapsulate all the 802.11 frames from wireless clients inside LWAPP frames and forward the LWAPP frames to the controller.
GLOSSARY
Access Point ( AP )
An entity that contains an 802.11 medium access control ( MAC ) and physical layer ( PHY ) interface and provides access to the distribution services via the wireless medium for associated clients.
LWAPP APs encapsulate all the 802.11 frames in LWAPP frames and sends them to the controller to which it is logically connected.
Light Weight Access Point Protocol ( LWAPP )
This is a generic protocol that defines the communication between the Access Points and the Central Controller.
Mobile Node ( MN )
A roaming 802.11 wireless device in a wireless network associated with an access point. Mobile Node and client are used interchangeably.
Rogue
Any 802.11 device which is not part of the RF network is a Rogue device.
Ad-hoc Network
A set of mobile devices within direct communication range establishing a network among themselves for transmitting data, without the use of a Access point is called a ad-hoc network.
Rogue Ad-hoc Client
Any 802.11 client which is part of that ad-hoc network, but not in the trusted list.
Service Set Identifier ( SSID )
SSID is a unique identifier that APs and clients use to identify with each other. SSID is a simple means of access control and is not for security. The SSID can be any alphanumeric entry up to 32 characters.
RSSI
Received Signal Strength Indication (RSSI), the IEEE 802.11 standard defines a mechanism by which RF energy is to be measured by the circuitry on a wireless NIC. Its value is measured in dBm and ranges from -128 to 0.
Rogue Location Detection Protocol (RLDP)
RLDP is a protocol to detect and automatically contain rogue devices. When the controller discovers a rogue access point, it uses the Rogue Location Discovery Protocol (RLDP) to determine if the rogue is attached to your network. RLDP can be enabled/disabled per controller level.
LRAD (LWAPP RADIO)
Light Weight Access Point Protocol Radio basically ones own AP.
REFERENCE
[1] Wireless LAN Medium Access Control ( MAC ) and Physical Layer ( PHY ) Specifications.
[2] Draft-obara-capwap-lwapp-00.txt, IETF Light Weight Access Point Protocol.
Main OID:
ciscoLwappRogueMIB.1.3.6.1.4.1.9.9.610
66
Objects
Active
Status
6
Dependencies
Imported Objects
Objects
66 total| Object Name |
|---|
ciscoLwappRogueMIBThis MIB is intended to be implemented on all those
devices operating as Central Controllers, that
terminate the Light Weight Access Point Protocol
tunnel from Cisco Light-weight LWAPP Access Points.
This MIB provides information about the Rogue APs
and Clients that are detected by the controller.
The relationship between CC and the LWAPP APs
can be depicted as follows:
+......+ +......+ +......+
+ + + + + +
+ CC + + CC + + CC +
+ + + + + +
+......+ +......+ +......+
.. . .
.. . .
. . . .
. . . .
. . . .
. . . .
+......+ +......+ +......+ +......+
+ + + + + + + +
+ AP + + AP + + AP + + AP +
+ + + + + + + +
+......+ +......+ +......+ +......+
. . .
. . . .
. . . .
. . . .
. . . .
+......+ +......+ +......+ +......+
+ + + + + + + +
+ MN + + MN + + MN + + MN +
+ + + + + + + +
+......+ +......+ +......+ +......+
The LWAPP tunnel exists between the controller and
the APs. The MNs communicate with the APs through
the protocol defined by the 802.11 standard.
LWAPP APs, upon bootup, discover and join one of the
controllers and the controller pushes the configuration,
that includes the WLAN parameters, to the LWAPP APs.
The APs then encapsulate all the 802.11 frames from
wireless clients inside LWAPP frames and forward
the LWAPP frames to the controller.
GLOSSARY
Access Point ( AP )
An entity that contains an 802.11 medium access
control ( MAC ) and physical layer ( PHY ) interface
and provides access to the distribution services via
the wireless medium for associated clients.
LWAPP APs encapsulate all the 802.11 frames in
LWAPP frames and sends them to the controller to which
it is logically connected.
Light Weight Access Point Protocol ( LWAPP )
This is a generic protocol that defines the
communication between the Access Points and the
Central Controller.
Mobile Node ( MN )
A roaming 802.11 wireless device in a wireless
network associated with an access point. Mobile Node
and client are used interchangeably.
Rogue
Any 802.11 device which is not part of the RF network
is a Rogue device.
Ad-hoc Network
A set of mobile devices within direct communication
range establishing a network among themselves for
transmitting data, without the use of a Access point
is called a ad-hoc network.
Rogue Ad-hoc Client
Any 802.11 client which is part of that ad-hoc network,
but not in the trusted list.
Service Set Identifier ( SSID )
SSID is a unique identifier that APs and clients
use to identify with each other. SSID is a simple
means of access control and is not for security.
The SSID can be any alphanumeric entry up to 32
characters.
RSSI
Received Signal Strength Indication (RSSI), the IEEE 802.11
standard defines a mechanism by which RF energy is to be
measured by the circuitry on a wireless NIC. Its value is
measured in dBm and ranges from -128 to 0.
Rogue Location Detection Protocol (RLDP)
RLDP is a protocol to detect and automatically
contain rogue devices. When the controller discovers
a rogue access point, it uses the Rogue Location
Discovery Protocol (RLDP) to determine if the
rogue is attached to your network.
RLDP can be enabled/disabled per controller level.
LRAD (LWAPP RADIO)
Light Weight Access Point Protocol Radio
basically ones own AP.
REFERENCE
[1] Wireless LAN Medium Access Control ( MAC ) and
Physical Layer ( PHY ) Specifications.
[2] Draft-obara-capwap-lwapp-00.txt, IETF Light
Weight Access Point Protocol. MODULE-IDENTITY .1.3.6.1.4.1.9.9.610 |
ciscoLwappRogueMIBNotifs OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.610.0 |
cLRogueAdhocRogueDetectedThis notification is generated by the controller when a
a rogue is detected. The name of the AP that
detected this rogue is sent in the notification. NOTIFICATION-TYPE .1.3.6.1.4.1.9.9.610.0.1 |
ciscoLwappRogueMIBObjects OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.610.1 |
cLRogueConfig OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.610.1.1 |
cLRoguePolicyConfig OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.610.1.1.1 |
cLRogueAdhocRogueReportEnableThis object is used to turn on and off ad-hoc
rogue reporting. Setting this object to 'true'
will enable ad-hoc rogue reporting. Setting to
'false' will disable ad-hoc rogue reporting.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.9.9.610.1.1.1.1 |
cLRogueReportIntervalThis object specifies the rogue report interval,
which is the interval that monitor mode APs send
rogue detection details to the controller.rw Unsigned32 .1.3.6.1.4.1.9.9.610.1.1.1.2 |
cLRogueMinimumRssiThis object specifies the minimum value of RSSI
considered for detection of rogues.rw Integer32 (-128..-70) UNITS "dBm" .1.3.6.1.4.1.9.9.610.1.1.1.3 |
cLRogueTransientIntervalThis object specifies the rogue transient
interval.
A value of '0' specifies that an AP sends
rogue detection details to the controller
as soon as it detects a rogue.
A non-zero value specifies that an AP sends
rogue detection details to the controller if
it hears the rogue more than once in the specified
interval.rw Unsigned32 (0 | 120..1800) UNITS "seconds" .1.3.6.1.4.1.9.9.610.1.1.1.4 |
cLRogueClientNumThresholdThis object specifies the number of clients the Rogue AP
can have. A value of zero indicates no limitation on
the number of clients the Rogue AP can have.rw Unsigned32 .1.3.6.1.4.1.9.9.610.1.1.1.5 |
cLRogueDetectionSecurityLevelThis object specifies the rogue detection security level.
When the object has value of 'low', 'high' or 'critical',
controller uses pre-defined rogue detection parameters for
the specified security level.
When the object has value of 'custom', controller uses the
user configured rogue detection parameters.
low - security level is low
high - security level is high
critical - security level is critical
custom - customized security levelrw Enumeration .1.3.6.1.4.1.9.9.610.1.1.1.6 |
cLRogueValidateRogueClientsAgainstMseThe object specifies whether the controller validates
'valid' clients which are associating with rogue AP,
against MSE. A value of 'enable' indicates that the
controller does validates 'valid'clients which are
associating with rogue AP, against MSE. A value of
'disable' indicates that the controller does not
validates 'valid' clients which are associating
with rogue AP, against MSE.rw Enumeration .1.3.6.1.4.1.9.9.610.1.1.1.7 |
cLRogueAdhocRogueNotifEnabledThe object to control the generation of
cLRogueAdhocDetected notification.
A value of 'true' indicates that the agent generates
cLRogueAdhocDetected notification.
A value of 'false' indicates that the agent doesn't
generate cLRogueAdhocDetected notification.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.9.9.610.1.1.2 |
cLRogueRuleConfig OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.610.1.1.3 |
cLRuleConfigTableThis table provides the configuration needed
by the controller for classifying rogue APs.
The user defines the custom rules which are
used to classify the APs under different
classification types. When a new rule is created
priority will be assigned automatically by controller,
highest priority given to rule which are created first.
Also if user is changing the priority of a rule manually,
the new priority should not be used by any other existing rule. SEQUENCE OF CLRuleConfigEntry .1.3.6.1.4.1.9.9.610.1.1.3.1 |
cLRuleConfigEntryEach entry represents a conceptual row
(as identified by a rule name)in cLRuleConfigTable. CLRuleConfigEntry .1.3.6.1.4.1.9.9.610.1.1.3.1.1 |
cLRuleNameThis object represents the rule name to identify
this entry. SnmpAdminString .1.3.6.1.4.1.9.9.610.1.1.3.1.1.1 |
cLRuleRogueTypeThis object determines the classification applied
to the rogue AP that matches this rule.
friendly - known and acknowledged rogue AP.
malicious - unknown AP that matches user defined
malicious rules.
unclassified - an unknown AP that did not match malicious
or friendly rules.
custom - user can configure rogue detection parameters.rw Enumeration .1.3.6.1.4.1.9.9.610.1.1.3.1.1.2 |
cLRuleConditionsMatchThis object represents how the conditions
defined by corresponding instances of
cLConditionType, are matched under each rule.
all - all the conditions defined per rule should be matched
any - any conditions defined per rule can be matched.rw Enumeration .1.3.6.1.4.1.9.9.610.1.1.3.1.1.3 |
cLRulePriorityThis object is used to define the order in which the
rules will be applied. The rules will be applied from
lowest to highest and gaps are allowed.
Each rule must have and unique value for this object.rw Unsigned32 .1.3.6.1.4.1.9.9.610.1.1.3.1.1.4 |
cLRuleEnableThis object specifies whether this rule is enabled or not.
A value of 'true' specifies this rule is enabled.
A value of 'false' specifies this rule is disabled.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.9.9.610.1.1.3.1.1.5 |
cLRuleStorageTypeThis object represents the storage type for this conceptual
row.rw StorageType (SNMPv2-TC) .1.3.6.1.4.1.9.9.610.1.1.3.1.1.6 |
cLRuleRowStatusThis object represents the status column for a
conceptual row in this table. All writable objects
in this row may be modified when the row is active.rw RowStatus (SNMPv2-TC) .1.3.6.1.4.1.9.9.610.1.1.3.1.1.7 |
cLConditionConfigTableThis table represents the configuration of
conditions that can be applied to a rule. SEQUENCE OF CLConditionConfigEntry .1.3.6.1.4.1.9.9.610.1.1.3.2 |
cLConditionConfigEntryEach entry represents a conceptual row in
cLConditionConfigTable, as identified by a
specific condition name to be applied on a
specific rule name. CLConditionConfigEntry .1.3.6.1.4.1.9.9.610.1.1.3.2.1 |
cLConditionNameThis object represents the condition name. SnmpAdminString .1.3.6.1.4.1.9.9.610.1.1.3.2.1.1 |
cLConditionTypeThis object represents the condition type
for this condition associated with a rule.
managedSsid - matches managed SSID
rssi - required minimum RSSI
duration - limited to this time duration
clientCount - number of associated clients
noEncryption - no encryption rule
userConfigSsid - matches user configured SSIDrw Enumeration .1.3.6.1.4.1.9.9.610.1.1.3.2.1.2 |
cLConditionValueThis object represents the value associated
with the condition type as specified by
the corresponding cLConditionType instance.
If cLConditionType is 'userConfigSsid',
then corresponding 'cLConditionValue' can
only take on the value of zero.rw Integer32 .1.3.6.1.4.1.9.9.610.1.1.3.2.1.3 |
cLConditionEnableThis object indicates whether matching against
this condition is enabled or not. A value of 'true'
indicates matching against this condition is enabled.
A value of 'false' indicates matching against
this condition is disabled.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.9.9.610.1.1.3.2.1.4 |
cLConditionStorageTypeThis object represents the storage type for this conceptual
row.rw StorageType (SNMPv2-TC) .1.3.6.1.4.1.9.9.610.1.1.3.2.1.5 |
cLConditionRowStatusThis object represents the status column for a
conceptual row in this table. All writable objects
except cLConditionType in this row may be
modified when the row is active.rw RowStatus (SNMPv2-TC) .1.3.6.1.4.1.9.9.610.1.1.3.2.1.6 |
cLConditionRssiThis object specifies the minimum value of RSSI that
a rogue AP must have in order to match cLConditionType
of 'rssi'.rw Integer32 .1.3.6.1.4.1.9.9.610.1.1.3.2.1.7 |
cLConditionClientCountThis object specifies the minimum value of client count
that a rogue AP must have in order to match cLConditionType
of 'clientCount'.rw Unsigned32 .1.3.6.1.4.1.9.9.610.1.1.3.2.1.8 |
cLConditionNoEncryptionEnabledThis object specifies whether or not encryption is enabled.
A value of 'true' indicates that encryption is not enabled.
A value of 'false' indicates that encryption is enabled
for this condition.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.9.9.610.1.1.3.2.1.9 |
cLConditionManagedSsidEnabledThis object specifies whether or not managed SSID is enabled.
A value of 'true' indicates managed SSID is enabled.
A value of 'false' indicates managed SSID is not enabled
for this condition.rw TruthValue (SNMPv2-TC) .1.3.6.1.4.1.9.9.610.1.1.3.2.1.10 |
cLConditionDurationThis object specifies the minimum value of duration,
in seconds, a rogue AP must be present in order to match
cLConditionType of 'duration'.rw Unsigned32 UNITS "seconds" .1.3.6.1.4.1.9.9.610.1.1.3.2.1.11 |
cLConditionSsidConfigTableThis table represents the configuration of
SSID for a rule. This is applicable to
conditions within a rule which has the
corresponding cLConditionType taking on the value
of 'userConfigSsid'. SEQUENCE OF CLConditionSsidConfigEntry .1.3.6.1.4.1.9.9.610.1.1.3.3 |
cLConditionSsidConfigEntryEach entry represents a conceptual row in
cLConditionSsidConfigTable. CLConditionSsidConfigEntry .1.3.6.1.4.1.9.9.610.1.1.3.3.1 |
cLConditionSsidValueThis object represents the SSID value for this
condition associated with a rule. SnmpAdminString .1.3.6.1.4.1.9.9.610.1.1.3.3.1.1 |
cLConditionSsidStorageTypeThis object represents the storage
type for this conceptual row.rw StorageType (SNMPv2-TC) .1.3.6.1.4.1.9.9.610.1.1.3.3.1.2 |
cLConditionSsidRowStatusThis object represents the status column for a
conceptual row in this table. All writable objects
in this row may not be modified when the row is active.rw RowStatus (SNMPv2-TC) .1.3.6.1.4.1.9.9.610.1.1.3.3.1.3 |
cLRogueIgnoreListConfig OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.610.1.1.4 |
cLRogueIgnoreListTableThe table lists the APs, as identified by the AP's mac address,
which should not be treated as rogue by the controller.
These APs are the autonomous access points that have been
manually added to WCS. SEQUENCE OF CLRogueIgnoreListEntry .1.3.6.1.4.1.9.9.610.1.1.4.1 |
cLRogueIgnoreListEntryEach entry represents a conceptual row in this table.
There will be a row for each entry of the autonomous
APs which are manually added to WCS. When the autonomous
AP is no longer managed by WCS, the corresponding row
entry will be removed. CLRogueIgnoreListEntry .1.3.6.1.4.1.9.9.610.1.1.4.1.1 |
cLRogueIgnoreListMACAddressThis is the MAC Address of the AP to be put in the
rogue ignore list. MacAddress (SNMPv2-TC) .1.3.6.1.4.1.9.9.610.1.1.4.1.1.1 |
cLRogueIgnoreListStorageTypeThis object represents the storage type for this
conceptual row.rw StorageType (SNMPv2-TC) .1.3.6.1.4.1.9.9.610.1.1.4.1.1.2 |
cLRogueIgnoreListRowStatusThis is the status of the conceptual row.
All writable objects in this row may not be
modified when the row is active.rw RowStatus (SNMPv2-TC) .1.3.6.1.4.1.9.9.610.1.1.4.1.1.3 |
cLRldpAutoContainConfig OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.610.1.1.5 |
cLRldpAutoContainFeatureOnWiredNetworkThis object represents the RLDP Auto contain feature status.
disable - automatic containment of rogues on wired network
is disabled
enable - automatic containment of rogues on wired network
is enabled
NOTE: Using this feature may have legal consequences!!!rw Enumeration .1.3.6.1.4.1.9.9.610.1.1.5.1 |
cLRldpAutoContainRoguesAdvertisingSsidThis is the action with respect to auto containment feature,
that should be taken when switch detects rogues that are
advertising our SSID.
NOTE: Using this feature may have legal consequences!!!rw CLAutoContainActions .1.3.6.1.4.1.9.9.610.1.1.5.2 |
cLRldpAutoContainAdhocNetworksThis is the action with respect to auto containment feature,
that should be taken when adhoc networks are
detected by the switch.
NOTE: Using this feature may have legal consequences!!!rw CLAutoContainActions .1.3.6.1.4.1.9.9.610.1.1.5.3 |
cLRldpAutoContainTrustedClientsOnRogueApsThis is the action with respect to auto containment feature,
that should be taken when trusted clients that
are associated to rogue APs are detected by the switch.
NOTE: Using this feature may have legal consequences!!!rw CLAutoContainActions .1.3.6.1.4.1.9.9.610.1.1.5.4 |
cLRldpAutoContainLevelThis object is used to specify the level of auto containment.
The level actually denotes the number of APs that should be
used by the controller for auto containment.rw Integer32 .1.3.6.1.4.1.9.9.610.1.1.5.5 |
cLRldpAutoContainOnlyforMonitorModeApsThis object is used to specify if auto containment should be
done only using monitor mode APs or not.
disable - auto containment will be done using all APs
irrespective of the mode
enable - auto containment will be done only using monitor
mode APs.rw Enumeration .1.3.6.1.4.1.9.9.610.1.1.5.6 |
cLRogueApConfig OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.610.1.1.6 |
cLRogueApTableThe table lists the configured rogue APs in the system. SEQUENCE OF CLRogueApEntry .1.3.6.1.4.1.9.9.610.1.1.6.1 |
cLRogueApEntryAn entry containing contains management information
of a particular rogue AP.
An entry can be created, or deleted by using
cLRogueApRowStatus. CLRogueApEntry .1.3.6.1.4.1.9.9.610.1.1.6.1.1 |
cLRogueApMACAddressMAC Address of a rogue AP. MacAddress (SNMPv2-TC) .1.3.6.1.4.1.9.9.610.1.1.6.1.1.1 |
cLRogueApClassTypeThis object specifies the type of a rogue AP.
friendly - existing known, Acknowledge, and Trust missing
rogue states are classified as Friendly.
malicious - unknown AP that could be a threat.
unclassified - an unknown AP or rogue AP is identified
but it does not belong to Friendly or
Malicious rogue types.
custom - AP that matches user defined custom rules.rw Enumeration .1.3.6.1.4.1.9.9.610.1.1.6.1.1.2 |
cLRogueApStateThis objects specifies the state in which
the rogue AP is.
pending - a read-only value indicates that rogue AP
can not be state to any of the following
type.
alert - rogue AP can be a potential threat.
Trap will be sent out to trap recipients.
detectedLrad - a read-only value indicates that a LRAD
that got detected as rogue.
known - a read-only value indicates that an internal
AP which is not on the same switch.
acknowledge - a read-only value indicates that an external
AP whose existence is acceptable and not a
threat(probably from vendor other than
cisco).
contained - containment is initiated and ongoing.
threat - rogue AP is found on wired network.
containedPending - a read-only value indicates that no AP
resources available for containment.
knownContained - a read-only value indicates that no longer
used.
trustedMissing - rogue AP is friendly but there is no slot
for friendly AP.
initializing - a read-only value indicates that rogue
AP is being initialized.
For a friendly rogue AP, only two states are valid:
'known' and 'acknowledge'.
'known', 'knownContained' and 'trustedMissing'
can appear in known rogue list.
Known rogues can be pre-provisioned and known rogues
state can be changed to 'alert'.rw Enumeration .1.3.6.1.4.1.9.9.610.1.1.6.1.1.3 |
cLRogueApStorageTypeThis object represents the storage type for this
conceptual row.rw StorageType (SNMPv2-TC) .1.3.6.1.4.1.9.9.610.1.1.6.1.1.4 |
cLRogueApRowStatusThe status of the conceptual row.
All writable objects in this row may be modified when
the row is active.rw RowStatus (SNMPv2-TC) .1.3.6.1.4.1.9.9.610.1.1.6.1.1.5 |
ciscoLwappRogueMIBConform OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.610.2 |
ciscoLwappRogueMIBCompliances OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.610.2.1 |
ciscoLwappRogueMIBGroups OBJECT IDENTIFIER .1.3.6.1.4.1.9.9.610.2.2 |