Controlling WLAN
Provides information about wireless APs detected on wireless network interfaces and restricts unauthorized AP connections. Provides visibility into APs in wireless LAN environments. In macOS Sonoma 14.5 or higher environments, Location Services permission is mandatory to obtain wireless LAN SSID information. If this permission is not enabled, the app cannot collect network information or perform management functions.
- Can secure visibility into authorized/unauthorized APs by collecting AP lists.
- Can prevent security incidents by disabling AP mode of wireless LAN interfaces.
- Go to Policy in the top menu.
- In the left Policy menu, go to Policy > Node Policy > Node Action.
- In the Node Action management window, find and click Controlling WLAN.
Below are Basic Settings.
- For CWP Message, add a message to display according to the policy.
- For Label, adding a label allows you to categorize the plugin with a custom label displayed in the "Description" input field.
Below are Plugin Settings.
- AP Information Collection Target: Collects information about detected and connected SSIDs on WLAN interfaces.
- AP Connection Control: Specifies whether to disconnect unauthorized wireless APs.
- Allowed AP Search Method: Selects the method to define allowed SSIDs. (Select WLAN Group, Enter SSID, Use Regular Expression)
- Allowed Wireless LAN Group: Select the allowed WLAN group from the dropdown.
- Control Cycle: Specifies the cycle for checking if the connected AP is an allowed AP. (Seconds - Minutes)
- Control Grace Period: Specifies the AP connection allowance time for updating the allowed AP list. (Seconds - Minutes)
- Blocking Notification: Selects the method to notify the user when AP connection is blocked. (Agent Popup or Code Authentication)
- Private Wi-Fi Address Control: In macOS Sequoia or higher versions, disables the private Wi-Fi address option to ensure the device's MAC address does not change upon network connection.
- Control Method: If 'Change Setting Value' is selected, only the value change is performed, and a reboot is required for application. If 'Apply Immediately' is selected, the network interface restarts immediately, which may cause wireless LAN disconnection.
- Notification Option: Specifies the notification method according to 'Control Method'. If 'No notification' is selected for the 'Apply Immediately' option, the network interface restarts immediately after the setting change.
- Application Delay: If 'User Notification' is selected for the 'Apply Immediately' option, you can set the time to display the notification before immediate application.
- Location Services Allowance Guide Message: Enter the guide message to display to the user when requesting Location Services permission.
- Adjust and enter CWP Message, Condition Settings, and Plugin Settings based on network requirements.
- Click the Modify button.
- In the left Policy menu, go to Node Policy.
- In the Node Policy window, click Default Policy.
- Find Node Action Settings and click Assign.
- In the Available items, find Controlling WLAN and drag it to the Selected items.
- Click the Add button.
- Click the Modify button.