Chapter 6 Deploying Wireless Networks : Wireless network monitoring : Monitoring rogue APs : On-wire rogue AP detection technique : MAC adjacency
  
MAC adjacency
If an access point is also a router, it applies NAT to WiFi packets. This can make rogue detection more difficult. However, an AP’s WiFi interface MAC address is usually in the same range as its wired MAC address. So, the MAC adjacency rogue detection method matches LAN and WiFi network MAC addresses that are within a defined numerical distance of each other. By default, the MAC adjacency value is 7. If the AP for these matching MAC addresses is not authorized in the FortiGate unit configuration, that AP is deemed an ‘on-wire’ rogue.