Answer the question
In order to leave comments, you need to log in
How to block an address (MAC - IP)?
Good afternoon colleagues!
Question from the network troubleshooting segment ;-)
There is a network 192.168.1.0/24 , the gateway is 192.168.1.1 (Mikrotik);
The first ten addresses 192.168.1.2-192.168.1.11 - Ubiquiti UniFi APLR;
The rest 192.168.1.15-192.168.1.254 - DHCP Clients (distribution via WiFi).
The grid is open (it should always be open).
Someone took a point (it is not known in what place, it is not known which manufacturer), and configured 192.168.1.1 on it, after which a collapse formed in the network.
Now, as you understand, clients have Internet for 5 minutes, and they don’t have it for 5 minutes, and so on cyclically.
The MAC address of this point, theoretically (practically) can be found out.
Please tell me, maybe you know the tools that will allow you to block this point in this network segment? Or advise how best to do so that in the future such a situation would not happen again?
Thanks in advance for your answers.
Answer the question
In order to leave comments, you need to log in
1. Determine the mac address of the intruder using the ping and arp commands with the "valid" gateway turned off.
2. In the software of access points, enter the mac address of the offender in the black list.
3. Profit.
It's extremely hard to make sure it doesn't happen again. This IP does not have "on the forehead" mechanisms of protection against such attacks. Some switches can, but from the description, your hardware can't.
There is a network 192.168.1.0/24 , the gateway is 192.168.1.1 (Mikrotik);
On local interfaces, enable reply-only or view traffic segmentation.
In the ARP list, manually bind the mac-addresses and ip-addresses of the router.
Make a rule that will stupidly kill the left udp 67\68 from other mac addresses.
Additionally look for microtik DHCP snooping
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question