Are Cisco and other AP controller vendors going to remove this option from their software? (If they're shipping a checkbox that is always illegal to enable, why aren't they subject to enforcement action?)
Are Cisco and other AP controller vendors going to remove this option from their software? (If they're shipping a checkbox that is always illegal to enable, why aren't they subject to enforcement action?)
"Containment can have legal implications when launched against neighboring networks. Ensure that the rogue device is within your network and poses a security risk before you launch the containment."
[1]http://www.cisco.com/c/en/us/support/docs/wireless/4400-seri...
Cisco seems to think this is perfectly fine to do to rouge APs connected to an organization's wired network, however.
Note that the Marriott enforcement action concerned the use of personal access points not connected to a Marriott network.
I don't see any basis in the Communication Act for making this distinction though. 47 U.S.C. Section 333, the law Marriott violated, says: "No person shall willfully or maliciously interfere with or cause interference to any radio communications of any station licensed or authorized by or under this chapter or operated by the United States Government." From the Cisco materials mentioned above, it seems the mitigation method involves sending fake de-authentication packets over the air. That also seems like intentional interference to me!
It sounds like the AP being on your network is what constitutes the security risk. I doubt the FCC would have a problem with a network administrator taking action like that. Unrelated APs are different.
> 47 U.S. Code § 333 - Willful or malicious interference
>
> No person shall willfully or maliciously interfere with
> or cause interference to any radio communications of any
> station licensed or authorized by or under this chapter
> or operated by the United States Government.I guess if someone is impersonating your SSID then this feature could be useful.
http://www.fcc.gov/document/marriott-pay-600k-resolve-wifi-b...
University Wi-Fi blocking is usually targeted at APs that students have attached to University network drops without permission, which is a completely different thing.
However, the FCC did not appear to draw a distinction, which is interesting.
At my university, the wireless APs would scan for others and try to detect if they were on-network using a student's auth. They'd tell the student to remove the AP if they wanted to continue to have access to the school network. Wireless, off-network hotspots were allowed, provided they weren't impersonating the school network.