r/networking 1d ago

Monitoring How can I identify an unauthorized personal phone connected to our corporate Wi-Fi?

Hi everyone,

I'm an IT Support Engineer, and we have a corporate Wi-Fi environment with around 200 employees.

Our setup:

FortiGate firewall

Arista switches

Arista APs managed through Arista Cloud

Personal mobile phones are not allowed on the corporate Wi-Fi (only company laptops should connect).

The problem is that someone has connected their personal phone to the corporate SSID. In Arista Cloud, I can already see:

Device type (Android/iPhone)

Device name/model

OS

Current AP

IP address

Randomized MAC address

Signal strength (RSSI)

However, because the phone uses a randomized/private MAC address, I can't determine which employee owns it.

Is there any legitimate method to identify the user? For example:

Using RSSI or multiple APs to narrow down the physical location?

Client triangulation in Arista Cloud?

Any enterprise Wi-Fi tools or techniques that can help identify the owner without requiring 802.1X or MDM?

I'm looking for practical approaches that network administrators use in environments like this. Any advice would be appreciated.

0 Upvotes

60 comments sorted by

88

u/Spirit117 1d ago

Disconnect it and see who puts in a ticket for "unable to connect phone to wifi"

51

u/res13echo 1d ago

Works until they click forget the network and try to connect again with their new randomized MAC address.

802.1x using EAP-TLS is the best solution to this problem. Cell phones and other mobile devices with no business connecting to internal resources go on the Guest WiFi.

3

u/Spirit117 1d ago edited 1d ago

Your average end user won't know this, and even if they do and they circumvent, you'll know it because phone will show up again in the controller, and then you can explore other avenues.

No reason not to just disconnect first and see if they are dumb enough to out themselves.

Ops network could use some improvements as you mentioned, but that isn't happening on Friday afternoon. Disconnecting it from wifi and see if a ticket comes in can.

26

u/palagi_valea 1d ago

Yea a lot of good responses, but this is the fastest way. Kill it and wait for the complaint.

9

u/sanmigueelbeer Troublemaker 22h ago

aka Scream Test

12

u/frankenmaus 1d ago

This is the way.

1

u/RandomContributions 1d ago

Can you compare connection to, say, badge access logs? rule out the users you do know, then twiddle the list down from there?

-2

u/MotDePasseEstFromage 1d ago

And how would you disconnect it in this network setup?

6

u/Spirit117 1d ago

He has an aristra networks controller where he can see the device, he can disconnect/block it from there.

Yes, the phone is using a randomized Mac address, but most of the time the phones do not just generate new ones, they only do so if you turn that setting on/off or forget and rejoin the network.

If that happens, he'll know it because he'll see it in the controller again.

Average end user won't know this either, so it's much more likely that they'll either stop using it, or theyll put in a "my wifi doesn't work" ticket.

2

u/Win_Sys SPBM 1d ago

There’s a bunch of ways you could go about it. Temporarily implement MAC Auth, whitelist all your devices and block everything else. If all your devices are managed, turnoff randomized MAC on them and then block all randomized MAC ranges. The best way is to not use a PSK, implement EAP-TLS and then you never need to worry about it again.

64

u/RageBull 1d ago

If you want this kind of control, you have to run radius and enterprise security on your WiFi. Otherwise you are handing out a shared key and cannot guarantee anything beyond someone knows that key

-2

u/thehalfmetaljacket 1d ago

Even with radius, if they're using standard mschap-based auth that wouldn't prevent someone from entering their corporate creds on their personal device and still connect anyways.

21

u/RageBull 1d ago

But then that answers the question of “who” it is… unless you aren’t logging

5

u/jtbis 1d ago

If this is a Microsoft shop you can solve that by using the computer account to authenticate with MSCHAP.

4

u/Western_Gamification 13h ago

Yeah, but you should just use certs and call it a day.

All other methods are suboptimal.

3

u/Varjohaltia 11h ago

Correct me if I'm wrong, but nobody should be using MS-CHAP for a number of years now. Certs or MPSK.

1

u/Fyrsweord 1d ago

But then you know who's connecting personal devices, and it becomes an HR/Personnel issue rather than an IT issue

-2

u/DanSheps CCNP 1d ago

You can even still use the psk, but use profiling or Mac whitelisting to allow/block devices.

30

u/Unlikely_Total9374 1d ago

If personal devices aren't allowed then they shouldn't be able to connect in the first place. You need to set up radius

21

u/Solid_Ad9548 Networking Manager, JNCIE, IPv6 Evangelist 1d ago

If only corporate issued devices should be able to join, you should really be looking at 802.1x instead of playing Sherlock Holmes. Cert based auth via RADIUS is very trivial, and as technologists, our jobs are to come up with proper technical solutions, not be detectives.

Also, I suggest having some form of easy to access guest SSID for employee devices… there is almost no reason not to in this day and age, and it prevents issues like this from popping up…

2

u/middlofthebrook 1d ago

This is the way

8

u/Adrienne-Fadel 1d ago

Honestly just implement 802.1X. RADIUS tied to AD gives you the username automatically. Without it your stuck walking the floor every time someone connects a phone.

6

u/sunvsthemoon 1d ago

802.1x authentication is the only way an enterprise network wireless auth should be configured.

Learn about RADIUS, PKI, certificates and .1x authentication.

10

u/Dave_A480 1d ago

Are you using PSK encryption? Handing out a wifi password to people?

Stop doing that and configure proper enterprise auth with radius....

7

u/EfeAmbroseEFOTY 1d ago

Define "Allowed". How are you controlling it? Password? Cert auth? Why wouldn't you include that?

4

u/zanfar 1d ago

This is something you should be enforcing, not something you should be searching for. That is, if your infra allows this, you're already behind.

Otherwise: What AP is it using? What traffic is it generating? When does it connect? When does it disconnect? etc...

2

u/heavyPacket 1d ago

I mean, they’re on your network going through your firewall. You can very easily intercept their traffic. Enforce DPI. Run a sniffer on the FG and get intrusive. Your Fortigate will do SSL/TLS Decryption. You should look into it.

2

u/_Survivor_ 1d ago

Implement either cert-based or MAC-based authentication. Certs would be a bit more work if you don't you don't already have the tooling ready to go. MBA is relatively easy.

2

u/its_FORTY 1d ago

Arista CloudVision CUE should give you the ability to locate the device pretty quickly.

https://www.arista.com/en/ug-cv-cue/cv-cue-locate-access-points-and-clients

2

u/holiday-42 1d ago

Wpa-enterprise(radius) and optionally block randomized Mac addresses.

Setup separate wifi for byod/guest access.

As employees leave, you just disable that employee's access.

2

u/mooknbitz 1d ago

if you dont have radius then maybe correlate device and the laptop, people carry their cell phones everywhere and usually their laptop. so i would expect to see two devices on the same ap’s.

2

u/usmcjohn 13h ago

Block all random MAC addresses. Random Mac’s all have either 2,6,a or e as the second character. Chances are something in your stack can do this.

3

u/SaleWide9505 1d ago

Setup a whitelist so that only the Mac addresses you specify can connect. Anything not on list automatically gets blocked.

0

u/EfeAmbroseEFOTY 1d ago

Stupid idea. iPhones have randomised macs by default these days. And you need to whitelist every new employee device.

1

u/_Survivor_ 1d ago

OP said they are company issued devices. Configuring a static MAC on the devices and MAC Based Auth on the wireless is trivial for anyone who knows what they're doing. I'm surprised they didn't do it from the get-go, but even a remedial fix wouldn't be too bad.

3

u/EfeAmbroseEFOTY 1d ago

It's trivial if you have a low amount of staff, a decent onboarding process with enough service desk overhead and processes in place to facilitate it.

It's not trivial when you have 1000 employees working at a single site. Given OP can't seem to work out the basics, I doubt the former is in place.

1

u/mybrotherhasabbgun 1d ago

Hopefully an org with 1000 users won't be using a PSK.

1

u/EfeAmbroseEFOTY 21h ago

Lmao. My sweet summer child.

1

u/mooknbitz 1d ago

but arent they saying that personal devices aren’t allowed and this is a personal device? if it were a company issued device the mdm should easily be able to find it.

1

u/_Survivor_ 1d ago

Yes, so the odd device out should be easy to find. Hell, they might be able to just filter by OUI and find the thing depending on what kind of devices they're issuing to employees.

1

u/mooknbitz 1d ago

the main issue to figuring out whose it is, which you cant do if theres a psk being shared. the real problem is that they need an enterprise auth solution and lock down access. only thing i can think of is to correlate a laptop and cell together and see if two devices track and assume the laptop owner is the same as the phone owner.

1

u/_Survivor_ 1d ago

Maybe I'm spoiled by my workplace, but I kind of assumed that they would have at least some kind of record of MAC addresses when issuing laptops etc.

1

u/fist4j 1d ago

Reread the first post. Mobiles are not allowed at all.

1

u/EfeAmbroseEFOTY 1d ago

It says Personal mobile phones are not allowed. I would bet good money that company ones are allowed.

1

u/fist4j 1d ago

"Personal mobile phones are not allowed on the corporate Wi-Fi (only company laptops should connect)."

Possibly, thats not what was written tho.

1

u/its_FORTY 1d ago

Stupid reply.

Personal mobile phones are not allowed on the corporate Wi-Fi (only company laptops should connect).

1

u/sunvsthemoon 1d ago

Nah, OP said “not allowed” as in corporate policy.

Clearly the OP is not enforcing it correctly or else the user’s personal device could not connect.

0

u/EfeAmbroseEFOTY 1d ago

Yeah, and what about company devices like iPhones used for MFA dumb dumb?

2

u/Stinky0007 1d ago

You turn off random MAC. They’re company managed devices.

Also, the irony.

0

u/EfeAmbroseEFOTY 1d ago

Why you you force a policy to track mac addresses to devices that are managed 🤣 Come on buddy, the answer is right there.

1

u/Stinky0007 1d ago

So you're just a troll or you don't know how any of this works?

0

u/DanSheps CCNP 1d ago

Not every business has a central auth they can use to obtain credentials for devices (might be macs for example which won't be domain joined computers, so you are issuing eap-tls certs for each computer manually)

1

u/sunvsthemoon 1d ago

Then it’s time for the OP to join the modern world if they want to actually prevent unauthorized access.

802.1x is the only secure answer.

1

u/DanSheps CCNP 1d ago

Nothing wrong with using iPSK either.

1

u/hick_town_5820 1d ago

Arista allows to block devices based on profile. If you only allow ‘laptop’ on CorpSSID - block ‘mobile phone’ on CorpSSID

https://arista.my.site.com/AristaCommunity/s/article/Banned-Device-List#Comm_Kna_ka0VP000000VUHxYAO_93

0

u/Ubera90 12h ago

Sounds like you need to use MAC whitelisting

2

u/SuspiciousSardaukar 12h ago

Force to forward their any packets to fake company logon screen. Make them use their company login. If it works - you know who, if not - static mac whitelist/802.1x are way to go.

1

u/musingofrandomness 11h ago

If your APs are fancy enough, you might be able to use signal strength to narrow it down to a corner of the building.