Jump to content

Unknown / unwanted Netgear FS726T 24 Port Switch on my Network?


Recommended Posts

Posted (edited)

Just having a shufty in DHCP to check everything was okay and came across an IP address lease with no name. I can ping it. So I put the IP address into a browser and lo and behold it's a Netgear FS726T Smart Switch - password protected.

 

We've never had this make/model onsite. Now bemused and baffled and a bit angry in case some muppet has brought their own kit in and plugged it in for some reason?!

 

We're a biggish site but we can't see it anywhere after a trawl. Any ideas? I have installed the Netgear Smart Control Centre utility but it can't find it.

Edited by tech_guy
Posted
If what Domino suggests doesn't work, go on the comms cabinet after hours, unplug 1 building at a time, ping it, once you found the building, go to that comms cabinet, unplug 1 room at a time, rinse and repeat until you find the room. It is a time consuming method, but it worked when I had to find equipment which was plugged in and I didn't want!
Posted
Can you set a Deny in DHCP so it can't get an address? Not sure if this'll stop it from passing traffic, but if it does, you'll quickly find it when people squeal about it!
Posted

Not having an IP address will do nothing for blocking it from functioning, as the IP is purely for the web admin console on this model.

I assume you've tried the default password for the switch.. if not and it works you could always setup vLan's on it so that the attached devices can't connect... that will certainly get a few calls.

 

otherwise the only trick is unplug stuff til it stops responding and narrow it down that way.

Posted
Not having an IP address will do nothing for blocking it from functioning, as the IP is purely for the web admin console on this model.

 

Thought that may be the case. Could it be in a suspended ceiling somewhere? Seen that trick pulled a few times. The idea of pulling links until it goes offline seems to be best.

Posted (edited)

Don't know what your other switches are, so just few starters for 10. You should be able to find the MAC address out from DHCP so you could do show mac address-table address, this would tell you what port on what switch this is connected to (if its a trunk then do the same on the next switch up). show cdp neighbors can also give you a starting point as would show lldp neighbors (cisco) show lldp info remote-device (HP/ Others) I think. The other commands tend to work on most switches the outputs are shown in different ways but it should start getting you to the physical switch port that the switch is connected to, then the rest is down to finding out where its terminated.

 

Oh and just a word to the wise unplugging sections of your networks to find errant devices is like carpet bombing to swat a fly, although you will take down the fly the collateral damage to the rest of your network and its users is a little much! we have far better tools than carpet bombing to find devices on our networks.

Edited by HPlum78
Posted

Oh and just a word to the wise unplugging sections of your networks to find errant devices is like carpet bombing to swat a fly, although you will take down the fly the collateral damage to the rest of your network and its users is a little much! we have far better tools than carpet bombing to find devices on our networks.

 

Not really that much of a "carpet bombing", more like "Laser Guided bomb" ;)

I'd class us as a fairly large site with 13 different buildings, and it only takes about 10 seconds to disconnect the Cat 5 uplink cable from each building's fibre link, see if the device has stopped responding and then reconnect. For most users at the end of a day they would not notice the small blip and at least provides a rough location to perform a more in depth search.

Using the lookup tables on switches only works if the switch has an interface you can use, and records that information.

Posted (edited)
Each to their own, I have just ran this by the network guys at the uni and they have just said yeah that's what to do, how about you start at 16:00 hrs and then at 16:01 clear your desk and collect your cards from the front desk! I suppose this can only happen in the primary and secondary education sectors! Edited by HPlum78
Posted

Schools are *very* different places to universities. A university requires 24 hour networking. Schools more than often don't. Here, 5pm is our 'end of guarenteed service' time. So, things can and do get turned off after that time for diagnostics etc...

 

We don't have the time, funding or staff for more formal methodology of tracking things down. The fact you have 'network guys' indicates the difference - we have "me" and "my technician". :)

Posted

I can't do it here - too much stuff attached all over the place that has hissy fits if it loses the network and also users in at all sorts of weird and wonderful hours. Nightmare at times trying to do certain tasks.

 

We're thinking someone has it stuffed it in a cupboard or the like doing something we haven't been told about.

 

It's recent though as it wasn't knocking about the other week.

 

We'll find it soon.

 

Thanks for all your comments. I'll let you know the outcome!

Posted

Might it be time to introduce some form of NAP/NAC? To prevent such things in future?

 

I know its a pain to admin, but it does cut down massively on incidents (we run it here to prevent people plugging their random devices in all over the place).

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...