Chapter 6 Deploying Wireless Networks for FortiOS 5.0 : Wireless network monitoring : Monitoring rogue APs : On-wire rogue AP detection technique
  
On-wire rogue AP detection technique
Other APs that are available in the same area as your own APs are not necessarily rogues. A neighboring AP that has no connection to your network might cause interference, but it is not a security threat. A rogue AP is an unauthorized AP connected to your wired network. This can enable unauthorized access. When rogue AP detection is enabled, the On-wire column in the Rogue AP Monitor list shows a green up-arrow on detected rogues.
Rogue AP monitoring of WiFi client traffic builds a table of WiFi clients and the Access Points that they are communicating through. The FortiGate unit also builds a table of MAC addresses that it sees on the LAN. The FortiGate unit’s on-wire correlation engine constantly compares the MAC addresses seen on the LAN to the MAC addresses seen on the WiFi network.
There are two methods of Rogue AP on-wire detection operating simultaneously: Exact MAC address match and MAC adjacency.