Hi All,
I didn't think about this until now about asking the community. Our client has a location that we get alerts for all the time for rogue access points being detected and contained. When we can get alerts it says the SSID that was broadcasted, however when I check the dashboard there is nothing there about the AP. Few questions:
The rogue aps need to be physically connected to the network by Ethernet?
Can they be connected to any live Ethernet outlet in the building?
Each device has its own Mac, do I don't see how you can impersonate another?
I have read several articles about this, and I'm trying to understand better what to look for. I see the alerts at least several times a month. I hope this all makes sense as I'm trying to get the alerts to stop legitimate or not. Annoying, however the alerts wouldn't be firing if something was triggering, thoughts?
Thanks