Enable Rogue AP Containment vs "friendly-ap" vs "rogue-ap" roles

jef
jef Posts: 39  Freshman Member
First Comment First Anniversary
edited May 2024 in Wireless

What does "Enable Rogue AP Containment" actually do?

And what does it have to do with the "roles" of 'friendly-ap" and 'rogue-ap'?

If I have marked all unknown AP's as rogue in the "monitor" area. That does what to those devices?

If they happen to be attached to the zyxel gateway network, then any client from that AP would be rejected?

I did look it up in the manual, the answer didn't help:

Enable Rogue AP Containment = Select this to enable rogue AP containment.

Best Answers

  • Zyxel_Judy
    Zyxel_Judy Posts: 1,674  Zyxel Employee
    Zyxel Certified Network Engineer Level 2 - Nebula Zyxel Certified Network Engineer Level 2 - Switch Zyxel Certified Network Engineer Level 2 - Security Zyxel Certified Network Engineer Level 1 - Nebula
    Answer ✓

    Hi @jef ,

    Thank you for bringing your concerns to our attention.

    Our current APs include support for 802.11w, also known as Protected Management Frames (PMF), is to enhance the security of wireless networks by protecting management frames from being spoofed or tampered with, so Rogue AP Containment is no longer necessary. Therefore, we plan to phase out Rogue AP Containment in an upcoming firmware update.

    Judy

    See how you've made an impact in Zyxel Community this year! https://bit.ly/Your2024Moments_Community

  • Zyxel_Judy
    Zyxel_Judy Posts: 1,674  Zyxel Employee
    Zyxel Certified Network Engineer Level 2 - Nebula Zyxel Certified Network Engineer Level 2 - Switch Zyxel Certified Network Engineer Level 2 - Security Zyxel Certified Network Engineer Level 1 - Nebula
    Answer ✓

    Hi @jef ,

    In a network configured for "WPA2" only, every client device must support WPA2 (AES) encryption to authenticate and connect successfully.

    On the other hand, a network set to "WPA2-mix mode" allows for the connection of devices using either WPA (TKIP) or WPA2 (AES) encryption standards, accommodating a broader range of client devices.

    Should you opt to disable or deselect the "WPA2-mixed" mode, be advised that devices only capable of supporting WPA (TKIP) encryption will not be able to connect to the specified SSID (Wi-Fi network name).

    Judy

    See how you've made an impact in Zyxel Community this year! https://bit.ly/Your2024Moments_Community

All Replies

  • Zyxel_Judy
    Zyxel_Judy Posts: 1,674  Zyxel Employee
    Zyxel Certified Network Engineer Level 2 - Nebula Zyxel Certified Network Engineer Level 2 - Switch Zyxel Certified Network Engineer Level 2 - Security Zyxel Certified Network Engineer Level 1 - Nebula
    Answer ✓

    Hi @jef ,

    Thank you for bringing your concerns to our attention.

    Our current APs include support for 802.11w, also known as Protected Management Frames (PMF), is to enhance the security of wireless networks by protecting management frames from being spoofed or tampered with, so Rogue AP Containment is no longer necessary. Therefore, we plan to phase out Rogue AP Containment in an upcoming firmware update.

    Judy

    See how you've made an impact in Zyxel Community this year! https://bit.ly/Your2024Moments_Community

  • jef
    jef Posts: 39  Freshman Member
    First Comment First Anniversary
    edited February 2024

    Thank you Judy, Wpa2 vs wpa2-mixed.. limits the PMF.. If I deselect "mixed" what do I loose?

  • Zyxel_Judy
    Zyxel_Judy Posts: 1,674  Zyxel Employee
    Zyxel Certified Network Engineer Level 2 - Nebula Zyxel Certified Network Engineer Level 2 - Switch Zyxel Certified Network Engineer Level 2 - Security Zyxel Certified Network Engineer Level 1 - Nebula
    Answer ✓

    Hi @jef ,

    In a network configured for "WPA2" only, every client device must support WPA2 (AES) encryption to authenticate and connect successfully.

    On the other hand, a network set to "WPA2-mix mode" allows for the connection of devices using either WPA (TKIP) or WPA2 (AES) encryption standards, accommodating a broader range of client devices.

    Should you opt to disable or deselect the "WPA2-mixed" mode, be advised that devices only capable of supporting WPA (TKIP) encryption will not be able to connect to the specified SSID (Wi-Fi network name).

    Judy

    See how you've made an impact in Zyxel Community this year! https://bit.ly/Your2024Moments_Community