Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Sharma_Harsh
New Contributor

What does Stop:Rogue Client mean?

I regularly find Logs similar to these in Firewall logs This does not fall in any of the pre formatted log formats or am i missing something ? 2018-03-31T03:51:04.665490+05:30 10.208.39.10 <00: 0C:29:5E:77:8B>Mojo Wireless Manager v8.2.0-408 : Stop: Rogue Client [android-7cd0c22] is active. : 10.208.39.10://Locations/CDAC_OLD_BLDG/Second Floor : 2018-03-30T22:21:04+00:00 : High : 1263800 : 5 : 66 : 780 : Stop: Rogue Client [android-7cd0c22] is active. The Client's details are: MAC address [F8:A9:63:AE:FA:D6], user name [--], vendor [Compal-Info], RSSI [--] dBm.

2018-03-31T03:51:07.540494+05:30 10.208.39.10 <00: 0C:29:5E:77:8B>Mojo Wireless Manager v8.2.0-408 : Stop: Rogue Client [android-8ea8f5e] is active. : 10.208.39.10://Locations/CDAC_OLD_BLDG/Second Floor : 2018-03-30T22:11:07+00:00 : High : 1263805 : 5 : 66 : 780 : Stop: Rogue Client [android-8ea8f5e] is active. The Client's details are: MAC address [4C:18:9A:CB:44:9F], user name [--], vendor [Unknown], RSSI [--] dBm. 

3 REPLIES 3
Toshi_Esumi
SuperUser
SuperUser

Do you happen to have Mojo APs and configured log output to the same syslog server you're getting from your FGT? These looks like Mojo's WIPS event log.

Sharma_Harsh

Yes We have Mojo Wireless AP's but I don't remember configuring WISP in syslogs servers, does it happen by default?

Toshi_Esumi

Then, you're asking a wrong group. Ask Mojo support instead. You need to understand how their WIPS feature work in order to understand their event log messages.

Labels
Top Kudoed Authors