Solved

ARP entries and server/router going awol.

Posted on 2013-01-14
7
356 Views
Last Modified: 2013-05-07
I do some IT support in a local school where quite often the server or the router are no longer pingable, shares disappear and no one can print via the server. This doesn't last but has been wrecking my head for a few weeks.

The arp table on a pc that can no longer communicate with the server or router shows the wrong mac address for the server or router's ip address. On looking up the mac address, the mac address belongs to an Apple or HTC iphone forexample. The school's network is primarily wireless.

Would this be down to the students in  the school assigning the server or router's ip address on their smartphones? Or could it be due to some fault in the unmanaged switches?

Your help is greatly appreciated.

Many thanks in advance,
Enda
0
Comment
Question by:endarona
  • 3
  • 3
7 Comments
 
LVL 30

Expert Comment

by:IanTh
ID: 38773901
why aren't you using dhcp for wireless thats the normal way
0
 

Author Comment

by:endarona
ID: 38773916
I am using DHCP but I have a suspicion that the students are manaully assigning the ip address of the server or router to their phones. That is my understanding of why the arp table shows an incorrect mac address associated with the server or router's ip address.
0
 
LVL 30

Expert Comment

by:IanTh
ID: 38773948
I dont understand how your students are using static tell them its against a policy in force and must use dhcp as they are breaking other essential services like servers shares etc
0
Microsoft Certification Exam 74-409

Veeam® is happy to provide the Microsoft community with a study guide prepared by MVP and MCT, Orin Thomas. This guide will take you through each of the exam objectives, helping you to prepare for and pass the examination.

 

Author Comment

by:endarona
ID: 38774171
Without knowing for sure, they are setting manual addresses on their phones to cause as much hassle as possible to the network. Again this is only my opinion but apart from the arp tables and being able to see what manufacturer of smartphone the mac addresses are, i have no way of tracking whose phone the mac addresses belong to.
0
 
LVL 30

Expert Comment

by:IanTh
ID: 38774213
ok I think iphone mac addresses start with 98:fe:94:x:x:x
0
 
LVL 10

Accepted Solution

by:
ddiazp earned 500 total points
ID: 38780634
If i was you i'd take the more aggressive approach. Chances is this is an intentional attack and i'd act based on that.

2 Things you could do:

1. Grab that mac address you see different, apply a macl, and block that mac address from accessing the network (from wireless server/router/controller).

2. Create static ARP entries to hardcode the mac address of that IP to the mac of the legitimate device. (this may not fully work but it would improve the scenario).
0
 

Author Comment

by:endarona
ID: 38782232
Thanks for the input. Unfortunately the switches are unmanaged. I'm going to go in and try Mike Timmons suggestion as per this link to keep kids smartphones off the wireless network

http://social.technet.microsoft.com/Forums/en/w7itprosecurity/thread/c5900c75-c031-4e02-9350-df7cb65bce04

This all stems from the mess created by Windows 7 showing the wireless key.
0

Featured Post

Windows Server 2016: All you need to know

Learn about Hyper-V features that increase functionality and usability of Microsoft Windows Server 2016. Also, throughout this eBook, you’ll find some basic PowerShell examples that will help you leverage the scripts in your environments!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Upgrade firmware on Engenius BH-ENS202Wi-Fi router 5 39
How to restrict all websites and allow only citrix website 5 45
CISCO Smartnet agreement 5 36
Patch panel 7 38
There are two basic ways to configure a static route for Cisco IOS devices. I've written this article to highlight a case study comparing the configuration of a static route using the next-hop IP and the configuration of a static route using an outg…
An article on effective troubleshooting
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question