Rouge IP address

If your problem doesn't fall into one of the other categories, report it here.

Moderator: Moderators

Post Reply
cj_mack
Posts: 53
Joined: Sun Dec 13, 2009 8:56 am

Rouge IP address

Post by cj_mack »

Hi,
I have been searching through the web usage and search history on my router. I came across some searches made by a rouge IP address.
I have also worked out that the device has used 80MB of un-metred data. I, cannot however, workout the MAC address or device ID.

The only way I can work out that it has happened, is that the flatmate has his daughters laptop and has plugged it directly into the router.
Every other device has a static IP assigned via MAC, and I don't believe he has the knowledge to fake a MAC address - I don't think he even knows how the router is setup to assign quotas.

What I want to know is how to record any connections so I have the MAC address available, then I can assign a quota onto that. In the meantime I have assigned a 100MB quota to the IP range dished out by the DHCP server, so it will be caught in there.

cj_mack
Posts: 53
Joined: Sun Dec 13, 2009 8:56 am

Re: Rouge IP address

Post by cj_mack »

Ok so this IP address has been accessing the web again. This time I was home, and nobody plugged into the router. Any ideas?

BikeMike
Posts: 108
Joined: Sat Jun 13, 2009 8:02 am
Location: Adelaide, South Australia

Re: Rouge IP address

Post by BikeMike »

If nobody is plugged in, must be over wireless (maybe an iphone or similar device?). If you want to prevent this it's good practice to lock down the whole network (not just DHCP range!) with a small, or even zero quota, then add fixed quotas for known devices only.

cj_mack
Posts: 53
Joined: Sun Dec 13, 2009 8:56 am

Re: Rouge IP address

Post by cj_mack »

That is what I have done for the mean time - a 100mb allowance for all unknown devices.

What I can't work out is that it is a wireless connection, which only allows known devices to connect.

What I think it is, (after some investigation) is the flatmate is booting his laptop off a USB drive into Mac OS. When he connects to the internet, the MAC address is recognised, but the static IP isn't being assigned, but a new one from the pool instead. Any ideas?

It is a netbook PC running some version of Mac OS.

BikeMike
Posts: 108
Joined: Sat Jun 13, 2009 8:02 am
Location: Adelaide, South Australia

Re: Rouge IP address

Post by BikeMike »

Even if you assign an IP it can be over-ridden by the client. To prevent this, tick the box in DHCP labeled "Block MAC addresses assigned a static IP that connect from a different IP"

http://bikemike.webnode.com/products/se ... le-router/

Post Reply