talksr Posted May 6, 2011 Posted May 6, 2011 Hi, we recently had a Trapeze RingMaster managed wireless system installed to our school. Every few weeks, I check my dhcp address leases on our RM CC4 server, and I keep seeing matts-iphone.local appearing. None of the staff have been given our wireless codes, they are strictly for the school laptops, and I am the only person who has or knows our encrypted key. The fact the name says iphone leads me to believe they can't be plugging in directly to the network and must be using our wireless. How can I monitor this. I have deleted the dhcp lease this afternoon and within 10 minutes, it was back, so clearly this is still active. I have had a good look on the RingMaster software and tried running reports with the mac address in question, but it is coming back with nothing. Maybe I am doing it wrong? Is there anything else I could try to try and work out how this node is connecting and from where? Thanks
plexer Posted May 6, 2011 Posted May 6, 2011 Rogue insecure wap somewhere that somebody has bought in? Ben 1
talksr Posted May 6, 2011 Author Posted May 6, 2011 That's a good point and I have had a good check around the building to make sure there are no devices plugged in. I hadn't thought of that, I thought maybe someone had brought a laptop in and plugged it in via Ethernet but named it iphone? The RingMaster system is supposed to give me an alarm for rouge ap's and it has nothing listed in alarms.
Hawkeyez Posted May 6, 2011 Posted May 6, 2011 You can (depending on how well the map was done) get a rough idea where the device is in respect to the school map. Our map was only a bmp rather than a scaled full on diagram, so can be abit off at times. I'm with plexer. We had (on old wireless) a member of staff plugged in there own AP.. and students was using that to connect there PSP's etc. 1
Hawkeyez Posted May 6, 2011 Posted May 6, 2011 That's a good point and I have had a good check around the building to make sure there are no devices plugged in. I hadn't thought of that, I thought maybe someone had brought a laptop in and plugged it in via Ethernet but named it iphone? The RingMaster system is supposed to give me an alarm for rouge ap's and it has nothing listed in alarms. We are always getting alarms for Rogue AP's, that when checked via "Rogue AP locator" (or whatever its called), its always in the homes that are close to the school grounds. We have thought about settings some of the AP's into counter-measure mode, but think its not quite needed atm. 1
accura2000 Posted May 6, 2011 Posted May 6, 2011 Just take the iphone mac address and get DHCP to assign it a useless ip address 1
plexer Posted May 6, 2011 Posted May 6, 2011 If you are running 2003 on your dhcp server you can install the mac filter callout dll to deny based on mac address or if you are using 2008 it is allready built in to dhcp. Ben 1
talksr Posted May 6, 2011 Author Posted May 6, 2011 How can I do that, I wasn't aware you could do it. Could I make a reservation and give a duff address?
accura2000 Posted May 6, 2011 Posted May 6, 2011 (edited) How can I do that, I wasn't aware you could do it. Could I make a reservation and give a duff address? Exactly... Dead easy and will proper annoy them lol Opps, i forgot, i have a dead ip range setup on my network assigned to dodgy mac addresses.... Edited May 6, 2011 by accura2000 1
talksr Posted May 9, 2011 Author Posted May 9, 2011 Very clever! I have just created one now. I gave them an IP of 169.254.0.1 that should put a stop to them using our network however they are! In the mean time, I will investigate further! Thanks again.
ricki Posted May 9, 2011 Posted May 9, 2011 HI You could put a reservation in dhcp with the mac address of the item with a silly ip and that will annoy them. Or you could put netstumbler on a laptop to find the access point. Or find the access point in dhcp put a silly reservation in for that. Just an idea. Richard 1
ricki Posted May 9, 2011 Posted May 9, 2011 Sorry Had a thought dont forget to report it to SLT and get it added to the Acceptable Use Policy. Richard 1
featured_spectre Posted May 9, 2011 Posted May 9, 2011 I would give them the IP address is 127.0.0.1...lol
AngryTechnician Posted May 9, 2011 Posted May 9, 2011 None of the staff have been given our wireless codes, they are strictly for the school laptops, and I am the only person who has or knows our encrypted key. Could someone have extracted it from the laptops? There are plenty of tools out there to do this, though I think you need admin rights most of the time. (Possibly not with XP).
pete Posted May 9, 2011 Posted May 9, 2011 How are you determining they're "using" the Wifi? A dhcp lease for an unknown device simply means your wireless controller / AP has handed out a lease (or proxied a lease from your dhcp server) as part of the handshake authentication process. That's normal - it doesn't mean they have access. Assuming your wireless is secured properly and you're using decent passwords, I wouldn't worry too much. If the kid's persistently messing about, find which matthew owns an iPhone and if he's messing about with it mid-lesson it'll get confiscated.
AlexB Posted May 10, 2011 Posted May 10, 2011 Are you running windows 7 clients? If so that secure wireless key is as secure as anyone allowed to use the client...
Marci Posted May 10, 2011 Posted May 10, 2011 This all depends how your Trapeze / specific SSIDs are set up... ours uses PEAP, certificate exchange, AD Authentication (ie: for a machine to be allowed onto the WiFi network it must reside in a specific GPO in AD and therefore must be a domain member). Do you have a plain WEP / WPA SSID set up on Ringmaster that allows access with just a key? If not, don't worry about folk sniffing out the key. Do you have Guest Access enabled which allows mobile devices on after being presented with a login screen via Ringmaster's WebPortal which authenticates the user against AD prior to allowing access? If so, they could be legitimately getting on that way... disable it. Also, it could be a jailbroken iPhone hooked up via cable to any Mac or PC, or by bluetooth... running appropriate tethering software, meaning the issue is nothing to do with Wireless, and is simply someone bridging thru their desktop PC - do your staff / students have access to enable bluetooth on school laptops / iMacs etc? Your Trapeze support provider would be the best folks to speak to about how your WiFi setup was done, and how to go about tracking rogue machines based on that. 1
cpjitservices Posted May 10, 2011 Posted May 10, 2011 even though they have an IP doesnt mean they can do any browsing right ?? Surely they'd have to have your proxy settings setup to even get on the internet (and authentication) and they wouldnt be able to browse the Network as they'd have to have a login to access any resources - not that I think you can on an IPhone anyway.
Marci Posted May 10, 2011 Posted May 10, 2011 Various iPhone apps allow access to various windows network resources such as network shares etc, but if these resources require authentication then the app will also require those auth details. 1
cpjitservices Posted May 10, 2011 Posted May 10, 2011 thought so - in which case I wouldnt worry but it wouldnt hurt to point the MAC at a useless IP 1
zag Posted May 10, 2011 Posted May 10, 2011 Ban the macs using dhcp. Or get a radius server on your managed wireless. Or mac whitelist filter on the wireless. I blogged about it here http://www.edugeek.net/blogs/zag/533-banning-ipods-blackberries-androids-home-laptops-your-school-network.html 1
talksr Posted May 10, 2011 Author Posted May 10, 2011 How are you determining they're "using" the Wifi? A dhcp lease for an unknown device simply means your wireless controller / AP has handed out a lease (or proxied a lease from your dhcp server) as part of the handshake authentication process. That's normal - it doesn't mean they have access. Assuming your wireless is secured properly and you're using decent passwords, I wouldn't worry too much. If the kid's persistently messing about, find which matthew owns an iPhone and if he's messing about with it mid-lesson it'll get confiscated. Hi, thanks for your post. All ethernet ports run through a gigabit stack. I have looked for the mac on the stack and there is nothing in any of the logs. Also the hostname "xyz's-iphone" was a hint it had to be wireless. As far as I know, iPhones can't connect via ethernet. Although you could easily change your hostname on a pc to "robs-iphone" I guess. I have made a duff reservation for it's mac as mentioned above. Not had a chance to check the dhcp leases yet!
talksr Posted May 10, 2011 Author Posted May 10, 2011 Ban the macs using dhcp. Or get a radius server on your managed wireless. Or mac whitelist filter on the wireless. I blogged about it here http://www.edugeek.net/blogs/zag/533-banning-ipods-blackberries-androids-home-laptops-your-school-network.html Thanks for your post, I will look into the whitelist filter or radius.
talksr Posted May 10, 2011 Author Posted May 10, 2011 even though they have an IP doesnt mean they can do any browsing right ?? Surely they'd have to have your proxy settings setup to even get on the internet (and authentication) and they wouldn't be able to browse the Network as they'd have to have a login to access any resources - not that I think you can on an IPhone anyway. True, but we are in London and on LGFL like most schools in this area. A little bit of knowledge and Google searching would soon reveal the famous proxy1.equinox poxy details currently used in most London schools. That's the internet taken care of. But true, they would not get access to any other resources, as Marci said, you would require auth details.
Marci Posted May 10, 2011 Posted May 10, 2011 Also the hostname "xyz's-iphone" was a hint it had to be wireless. As far as I know, iPhones can't connect via ethernet. Although you could easily change your hostname on a pc to "robs-iphone" I guess. I'm still betting jailbroken phone bluetooth-tethered (or via USB cable) to a laptop and bridging onto the network via that (using iBluever or similar app off cydia)...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now