Configuring a Wireless Rogue Access Point MAC Address Threshold
- Last Updated: April 2, 2026
- 2 minute read
- WhatsUp Gold
- Version 2026
The threshold will alert when any MAC addresses listed here broadcast SSID's in the given time interval.
Track devices using banned MAC addresses that behave like access points and broadcast SSIDs to wireless clients. See access point masquerading and SSID collisions between new and obsoleted access points, IoT devices using private networks, and more.
Configure a Wireless Rogue Access Point MAC Addresses threshold:
- Name. Used in the Threshold library and the title on the Alert Center Dashboard.
- Notification Policy. (Optional) Select the notification policy to apply to this threshold. The policy initiates notifications when an item is outside the configured threshold limits.
- Threshold Check Interval. Enter a time interval for Alert Center to check the WhatsUp Gold database for items that are out of the threshold limits.
Automatically resolve items no longer out of threshold. Select this option if you want Alert Center to automatically resolve items when they return to the value within the threshold limit.
Add Condition Rules:
- Duration. Compile a running total of all unrecognized SSID events during this time range or "rolling interval."
- Banned MAC Addresses. Enter any rogue MAC addresses separated by commas.
Select Applied Devices 
- Apply to All Devices. By default, the threshold monitors all applicable hosts.
Exclude Devices. Select to build or apply an exclusion list. - Click Apply this Threshold to Specific Devices to choose the hosts to which the threshold applies. Note: Configure the threshold check interval for a longer time than the sampling interval for thresholds relating to trends, such as percent utilization. Configure it for a time the same as (or similar to) the sampling interval when configuring a threshold for a health check.