Community discussions

MikroTik App
 
User avatar
Larsa
Forum Guru
Forum Guru
Topic Author
Posts: 1059
Joined: Sat Aug 29, 2015 7:40 pm
Location: The North Pole, Santa's Workshop

Prevent usage of SMHO WiFi-routers on corporate network?

Mon Jun 18, 2018 10:22 am

Is there a any way to prevent people to setting up "personal hotspots" using SMHO WiFi-routers on an enterprise office network? Presume the SOHO-router is assinged a correct ip-address from corporate DHCP-server and is using its own srs-nat, is there a way to detect and block thees kind of connections?
--

Any ideas are welcome!
Last edited by Larsa on Mon Jun 18, 2018 11:25 am, edited 2 times in total.
 
jarda
Forum Guru
Forum Guru
Posts: 7756
Joined: Mon Oct 22, 2012 4:46 pm

Re: Prevent usage of SMHO WiFi-routers on corporate network?

Mon Jun 18, 2018 10:32 am

You can play with ttl, but they can also. You can register mac but they can copy it. You can install a tool on the workstations that can check the locally assigned ip against the natted ip and report the difference to your server that can initiate the cut off. In case the stations belong into manageable domain...
 
User avatar
Larsa
Forum Guru
Forum Guru
Topic Author
Posts: 1059
Joined: Sat Aug 29, 2015 7:40 pm
Location: The North Pole, Santa's Workshop

Re: Prevent usage of SMHO WiFi-routers on corporate network?

Mon Jun 18, 2018 10:57 am

Thanks, I'll try TTL to start with!

Any suggestion on a decent value to start filtering on? Btw, is the internal TTL translated/terminated in src-nat and gets another TTL on the outbound side?
 
jarda
Forum Guru
Forum Guru
Posts: 7756
Joined: Mon Oct 22, 2012 4:46 pm

Re: Prevent usage of SMHO WiFi-routers on corporate network?  [SOLVED]

Mon Jun 18, 2018 11:04 am

If your network is flat switched, set ttl 1 to all packets going inside from outside.
viewtopic.php?t=14590
 
User avatar
Larsa
Forum Guru
Forum Guru
Topic Author
Posts: 1059
Joined: Sat Aug 29, 2015 7:40 pm
Location: The North Pole, Santa's Workshop

Re: Prevent usage of SMHO WiFi-routers on corporate network?

Mon Jun 18, 2018 11:23 am

Excellent, thanks for the pointer! Since it's "flat switched" (like the term btw ;-) it should probably work in this case.
 
jarda
Forum Guru
Forum Guru
Posts: 7756
Joined: Mon Oct 22, 2012 4:46 pm

Re: Prevent usage of SMHO WiFi-routers on corporate network?

Mon Jun 18, 2018 2:41 pm

It will work until the sharing device changes the ttl to higher value instead of dropping the packet. So as I said before...
 
User avatar
Larsa
Forum Guru
Forum Guru
Topic Author
Posts: 1059
Joined: Sat Aug 29, 2015 7:40 pm
Location: The North Pole, Santa's Workshop

Re: Prevent usage of SMHO WiFi-routers on corporate network?

Mon Jun 18, 2018 4:28 pm

Well, it's good enough to prevent a "normal" ad hoc installation and not for the professional villain with deeper technical knowledge :-)
 
User avatar
anav
Forum Guru
Forum Guru
Posts: 19323
Joined: Sun Feb 18, 2018 11:28 pm
Location: Nova Scotia, Canada
Contact:

Re: Prevent usage of SMHO WiFi-routers on corporate network?

Mon Jun 18, 2018 5:19 pm

POST a sign in all offices spaces.
"Any use of unauthorized Network Devices will be grounds for immediate dismissal! "

From a leadership point of view, why is it that employees feel they need wifi or more internet.
There may be a business case to provide better services!
 
User avatar
Larsa
Forum Guru
Forum Guru
Topic Author
Posts: 1059
Joined: Sat Aug 29, 2015 7:40 pm
Location: The North Pole, Santa's Workshop

Re: Prevent usage of SMHO WiFi-routers on corporate network?

Tue Jun 19, 2018 12:06 pm

Well, the regular access is somewhat limited because of previously misuse and someone got the brilliant idea to bypass that limitation. So i'm not quite convinced regarding the business case this time! :lol:
 
jarda
Forum Guru
Forum Guru
Posts: 7756
Joined: Mon Oct 22, 2012 4:46 pm

Re: Prevent usage of SMHO WiFi-routers on corporate network?

Tue Jun 19, 2018 3:13 pm

So how it works now?
 
User avatar
Larsa
Forum Guru
Forum Guru
Topic Author
Posts: 1059
Joined: Sat Aug 29, 2015 7:40 pm
Location: The North Pole, Santa's Workshop

Re: Prevent usage of SMHO WiFi-routers on corporate network?

Wed Jun 20, 2018 8:50 pm

Yes indeed!

Rumors say some of the co workers got very puzzled when their personal hotspot stopped working but were still able to use their laptop on the same connection.
 
jarda
Forum Guru
Forum Guru
Posts: 7756
Joined: Mon Oct 22, 2012 4:46 pm

Re: Prevent usage of SMHO WiFi-routers on corporate network?

Thu Jun 21, 2018 8:48 pm

Good. If they are smart, having cheapest mikrotik and reading this forum (even without all of it) they will easily overcome what you did.

Who is online

Users browsing this forum: Ahrefs [Bot], atejani, TeWe and 124 guests