Skip to main content

Overview

The rogue access point alert triggers when WIDS detects an unauthorized access point connected to your wired network. Rogue APs can create security vulnerabilities by bypassing network security controls.

Prerequisites

Configuring the alert

Rogue AP alert configuration

Configuration fields

FieldRequiredDescription
EnabledYesToggle to activate or deactivate the alert (default: on)
LabelNoCustom name for this alert instance
DescriptionNoAdditional notes about this alert
Alert typeYesSelect “Rogue AP”
ReceiverYesSelect from configured receivers
Company wideYesApply to all networks or select specific networks
Excluded networksNoNetworks to exclude when Company wide is enabled

Webhook event

This alert corresponds to the ALERT_ROGUE_AP_DETECTED webhook event. See Rogue access point webhook payload for integration details.

What to do when you receive this alert

  1. Review the alert details to identify the rogue AP’s MAC address and location
  2. Determine if this is an authorized device (e.g., a known wireless printer)
  3. If unauthorized, locate and disconnect the device from the network
  4. Consider blocking the device’s MAC address at the switch port level
  5. Contact Meter Support for assistance with investigation

Need help?

If you run into any issues or have questions, please reach out to our Support Engineering team by opening a ticket via the Dashboard: https://dashboard.meter.com/support
Last updated by Meter Support Engineering on 01/23/2026