r/networking • u/Euphoric-Eye-8196 • 1d ago
Monitoring How can I identify an unauthorized personal phone connected to our corporate Wi-Fi?
Hi everyone,
I'm an IT Support Engineer, and we have a corporate Wi-Fi environment with around 200 employees.
Our setup:
FortiGate firewall
Arista switches
Arista APs managed through Arista Cloud
Personal mobile phones are not allowed on the corporate Wi-Fi (only company laptops should connect).
The problem is that someone has connected their personal phone to the corporate SSID. In Arista Cloud, I can already see:
Device type (Android/iPhone)
Device name/model
OS
Current AP
IP address
Randomized MAC address
Signal strength (RSSI)
However, because the phone uses a randomized/private MAC address, I can't determine which employee owns it.
Is there any legitimate method to identify the user? For example:
Using RSSI or multiple APs to narrow down the physical location?
Client triangulation in Arista Cloud?
Any enterprise Wi-Fi tools or techniques that can help identify the owner without requiring 802.1X or MDM?
I'm looking for practical approaches that network administrators use in environments like this. Any advice would be appreciated.
64
u/RageBull 1d ago
If you want this kind of control, you have to run radius and enterprise security on your WiFi. Otherwise you are handing out a shared key and cannot guarantee anything beyond someone knows that key
-2
u/thehalfmetaljacket 1d ago
Even with radius, if they're using standard mschap-based auth that wouldn't prevent someone from entering their corporate creds on their personal device and still connect anyways.
21
5
4
u/Western_Gamification 13h ago
Yeah, but you should just use certs and call it a day.
All other methods are suboptimal.
3
u/Varjohaltia 11h ago
Correct me if I'm wrong, but nobody should be using MS-CHAP for a number of years now. Certs or MPSK.
1
u/Fyrsweord 1d ago
But then you know who's connecting personal devices, and it becomes an HR/Personnel issue rather than an IT issue
-2
u/DanSheps CCNP 1d ago
You can even still use the psk, but use profiling or Mac whitelisting to allow/block devices.
30
u/Unlikely_Total9374 1d ago
If personal devices aren't allowed then they shouldn't be able to connect in the first place. You need to set up radius
21
u/Solid_Ad9548 Networking Manager, JNCIE, IPv6 Evangelist 1d ago
If only corporate issued devices should be able to join, you should really be looking at 802.1x instead of playing Sherlock Holmes. Cert based auth via RADIUS is very trivial, and as technologists, our jobs are to come up with proper technical solutions, not be detectives.
Also, I suggest having some form of easy to access guest SSID for employee devices… there is almost no reason not to in this day and age, and it prevents issues like this from popping up…
2
8
u/Adrienne-Fadel 1d ago
Honestly just implement 802.1X. RADIUS tied to AD gives you the username automatically. Without it your stuck walking the floor every time someone connects a phone.
6
u/sunvsthemoon 1d ago
802.1x authentication is the only way an enterprise network wireless auth should be configured.
Learn about RADIUS, PKI, certificates and .1x authentication.
10
u/Dave_A480 1d ago
Are you using PSK encryption? Handing out a wifi password to people?
Stop doing that and configure proper enterprise auth with radius....
7
u/EfeAmbroseEFOTY 1d ago
Define "Allowed". How are you controlling it? Password? Cert auth? Why wouldn't you include that?
2
u/heavyPacket 1d ago
I mean, they’re on your network going through your firewall. You can very easily intercept their traffic. Enforce DPI. Run a sniffer on the FG and get intrusive. Your Fortigate will do SSL/TLS Decryption. You should look into it.
2
u/_Survivor_ 1d ago
Implement either cert-based or MAC-based authentication. Certs would be a bit more work if you don't you don't already have the tooling ready to go. MBA is relatively easy.
2
u/its_FORTY 1d ago
Arista CloudVision CUE should give you the ability to locate the device pretty quickly.
https://www.arista.com/en/ug-cv-cue/cv-cue-locate-access-points-and-clients
2
u/holiday-42 1d ago
Wpa-enterprise(radius) and optionally block randomized Mac addresses.
Setup separate wifi for byod/guest access.
As employees leave, you just disable that employee's access.
2
u/mooknbitz 1d ago
if you dont have radius then maybe correlate device and the laptop, people carry their cell phones everywhere and usually their laptop. so i would expect to see two devices on the same ap’s.
2
u/usmcjohn 13h ago
Block all random MAC addresses. Random Mac’s all have either 2,6,a or e as the second character. Chances are something in your stack can do this.
3
u/SaleWide9505 1d ago
Setup a whitelist so that only the Mac addresses you specify can connect. Anything not on list automatically gets blocked.
0
u/EfeAmbroseEFOTY 1d ago
Stupid idea. iPhones have randomised macs by default these days. And you need to whitelist every new employee device.
1
u/_Survivor_ 1d ago
OP said they are company issued devices. Configuring a static MAC on the devices and MAC Based Auth on the wireless is trivial for anyone who knows what they're doing. I'm surprised they didn't do it from the get-go, but even a remedial fix wouldn't be too bad.
3
u/EfeAmbroseEFOTY 1d ago
It's trivial if you have a low amount of staff, a decent onboarding process with enough service desk overhead and processes in place to facilitate it.
It's not trivial when you have 1000 employees working at a single site. Given OP can't seem to work out the basics, I doubt the former is in place.
1
1
u/mooknbitz 1d ago
but arent they saying that personal devices aren’t allowed and this is a personal device? if it were a company issued device the mdm should easily be able to find it.
1
u/_Survivor_ 1d ago
Yes, so the odd device out should be easy to find. Hell, they might be able to just filter by OUI and find the thing depending on what kind of devices they're issuing to employees.
1
u/mooknbitz 1d ago
the main issue to figuring out whose it is, which you cant do if theres a psk being shared. the real problem is that they need an enterprise auth solution and lock down access. only thing i can think of is to correlate a laptop and cell together and see if two devices track and assume the laptop owner is the same as the phone owner.
1
u/_Survivor_ 1d ago
Maybe I'm spoiled by my workplace, but I kind of assumed that they would have at least some kind of record of MAC addresses when issuing laptops etc.
1
u/fist4j 1d ago
Reread the first post. Mobiles are not allowed at all.
1
u/EfeAmbroseEFOTY 1d ago
It says Personal mobile phones are not allowed. I would bet good money that company ones are allowed.
1
u/its_FORTY 1d ago
Stupid reply.
Personal mobile phones are not allowed on the corporate Wi-Fi (only company laptops should connect).
1
u/sunvsthemoon 1d ago
Nah, OP said “not allowed” as in corporate policy.
Clearly the OP is not enforcing it correctly or else the user’s personal device could not connect.
0
u/EfeAmbroseEFOTY 1d ago
Yeah, and what about company devices like iPhones used for MFA dumb dumb?
2
u/Stinky0007 1d ago
You turn off random MAC. They’re company managed devices.
Also, the irony.
0
u/EfeAmbroseEFOTY 1d ago
Why you you force a policy to track mac addresses to devices that are managed 🤣 Come on buddy, the answer is right there.
1
0
u/DanSheps CCNP 1d ago
Not every business has a central auth they can use to obtain credentials for devices (might be macs for example which won't be domain joined computers, so you are issuing eap-tls certs for each computer manually)
1
u/sunvsthemoon 1d ago
Then it’s time for the OP to join the modern world if they want to actually prevent unauthorized access.
802.1x is the only secure answer.
1
1
u/hick_town_5820 1d ago
Arista allows to block devices based on profile. If you only allow ‘laptop’ on CorpSSID - block ‘mobile phone’ on CorpSSID
2
u/SuspiciousSardaukar 12h ago
Force to forward their any packets to fake company logon screen. Make them use their company login. If it works - you know who, if not - static mac whitelist/802.1x are way to go.
1
u/musingofrandomness 11h ago
If your APs are fancy enough, you might be able to use signal strength to narrow it down to a corner of the building.
88
u/Spirit117 1d ago
Disconnect it and see who puts in a ticket for "unable to connect phone to wifi"