uOS 1.38-AP Controller Enhancements: Rogue AP Detection

Options
Zyxel_Lynn
Zyxel_Lynn Posts: 183 image  Zyxel Employee
5 Answers First Comment Friend Collector First Anniversary
edited May 20 in Other Topics

Wireless Security: Rogue AP Detection for H Series Controllers

When acting as an AP controller, the H series firewall now supports Rogue AP detection to identify unauthorized wireless devices in the network.

Detection and Scanning

Managed APs can be configured to perform background scans every 30 minutes to detect nearby BSSIDs. 



Administrators can trigger manual scans using the "Detect Now" feature. The scan result includes a "Seen By" column, which helps locate rogue devices by showing which managed APs detected the signal.


Classification Rules

Administrators can define rules to automatically classify detected devices as suspected rogue APs based on criteria such as weak security (open networks), hidden SSIDs, unmanaged status, or specific SSID keywords.

Data Retention

Scan entries are retained in the system for up to 90 minutes. Each radio can track a significant number of entries of up to 256 per radio (512 for dual-radio APs and 768 for triple-radio APs).