Does this make enterprise/university use of rouge AP mitigation mechanisms illegal? Are Cisco and other AP controller vendors going to remove this option from their software? (If they're shipping a checkbox that is always illegal to enable, why aren't they subject to enforcement action?)
"Containment can have legal implications when launched against neighboring networks. Ensure that the rogue device is within your network and poses a security risk before you launch the containment."
[1]http://www.cisco.com/c/en/us/support/docs/wireless/4400-seri...
Cisco seems to think this is perfectly fine to do to rouge APs connected to an organization's wired network, however.
Note that the Marriott enforcement action concerned the use of personal access points not connected to a Marriott network.
I don't see any basis in the Communication Act for making this distinction though. 47 U.S.C. Section 333, the law Marriott violated, says: "No person shall willfully or maliciously interfere with or cause interference to any radio communications of any station licensed or authorized by or under this chapter or operated by the United States Government." From the Cisco materials mentioned above, it seems the mitigation method involves sending fake de-authentication packets over the air. That also seems like intentional interference to me!