CISCO-LWAPP-ROGUE-MIB

MIB Reference — IPNetwork Monitor · Updated September 14, 2026

All MIBsCISCO-LWAPP-ROGUE-MIB

Organization: Cisco Systems Inc.

Last Updated: 2017-03-21

Description: MIB for detecting, classifying, and generating alerts for rogue access points and clients on Cisco LWAPP wireless LAN controllers

Start monitoring vendor-neutral, standards-based MIB, any SNMPv3-capable network device (SNMP engine identity/boot/clock status) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

What Is CISCO-LWAPP-ROGUE-MIB?

CISCO-LWAPP-ROGUE-MIB is a Cisco vendor-specific MIB implemented on Wireless LAN Controllers (Central Controllers) that terminate the Light Weight Access Point Protocol (LWAPP) tunnel from Cisco lightweight access points. It models rogue access point and rogue client detection, exposing configuration objects such as cLRogueMinimumRssi, cLRogueClientNumThreshold, and cLRogueDetectionSecurityLevel alongside classification rule tables (cLRuleConfigTable with cLRuleName, cLRuleRogueType, cLRulePriority, cLRuleEnable) and condition tables (cLConditionConfigTable, cLConditionSsidConfigTable) used to score and classify detected 802.11 devices as rogue or trusted. It also exposes Rogue Location Discovery Protocol (RLDP) auto-containment controls (cLRldpAutoContainFeatureOnWiredNetwork, cLRldpAutoContainAdhocNetworks) and a cLRogueIgnoreListTable for excluding known devices from alerts. This data is useful for wireless security monitoring, detecting unauthorized APs and ad-hoc clients bleeding into the RF environment, and depends on CISCO-LWAPP-AP-MIB and CISCO-LWAPP-DOT11-CLIENT-MIB for the underlying AP and client object definitions; it is deployed alongside those MIBs on Cisco WLC platforms as part of ongoing CISCO-LWAPP-ROGUE-MIB SNMP monitoring of enterprise wireless security posture.

IPNetwork Monitor allows you to monitor SNMP objects defined in CISCO-LWAPP-ROGUE-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.

Supported Devices

  • Cisco Wireless LAN Controllers (WLC) terminating LWAPP/CAPWAP tunnels from lightweight access points

Monitoring Examples

An operator polls cLRuleConfigTable to confirm which classification rules (cLRuleRogueType, cLRulePriority) are active and enabled (cLRuleEnable), then checks cLRogueClientTotalDetectingAPs and cLRogueClientLastReported for a given rogue entry; a rising detecting-AP count combined with a recent cLRogueClientLastReported timestamp and no matching entry in cLRogueIgnoreListTable would flag an active, unaddressed rogue client near the coverage area.

What Can Be Monitored

  • rogue AP/client detection thresholds (RSSI, client count)
  • classification rule and condition table entries
  • RLDP auto-containment settings
  • rogue ignore list entries
  • detecting-AP counts and last-reported timestamps
Imported Objects

From CISCO-LWAPP-AP-MIB

cLApDot11IfTypeOBJECT-TYPE
cLApDot11RadioChannelNumberOBJECT-TYPE
cLApDot11RadioMACAddressOBJECT-TYPE
cLApIfSmtDot11BssidOBJECT-TYPE
cLApNameOBJECT-TYPE
cLApRogueApMacAddressOBJECT-TYPE
cLApRogueDetectedChannel
cLApRogueMode

From CISCO-LWAPP-DOT11-CLIENT-MIB

cldcClientMacAddressOBJECT-TYPE

From CISCO-SMI

ciscoMgmtOBJECT-IDENTITY

From SNMP-FRAMEWORK-MIB

SnmpAdminString

From SNMPv2-CONF

MODULE-COMPLIANCE
NOTIFICATION-GROUP
OBJECT-GROUP

From SNMPv2-SMI

Integer32
MODULE-IDENTITY
NOTIFICATION-TYPE
OBJECT-TYPE
Unsigned32

From SNMPv2-TC

MacAddress
RowStatus
StorageType
TEXTUAL-CONVENTION
TruthValue
OIDs

RFC description

Manages information about rogue access points and wireless clients detected by Cisco Lightweight Access Point Protocol controllers. Enables monitoring of unauthorized wireless devices using off-channel scanning and dedicated monitor mode capabilities.

Start monitoring Cisco Wireless LAN Controllers (LWAPP-based) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

Download CISCO-LWAPP-ROGUE-MIB