How to locate rogue AP?

Cooky

Golden Member
Apr 2, 2002
1,408
0
76
I'm seeing some rogue AP's & print servers on our wireless network that I suspect causing some problems.

Does anyone know how I can pin point their exact locations? Would be nice if it gives louder beeps when I'm closer to their locations.

Right now I could only find their approx locations by the radios that are seeing the MAC addresses but it's not good enough.
 

spyordie007

Diamond Member
May 28, 2001
6,229
0
0
There are several tools that are very good at giving you a location on floor plans, but (so far as I know) none of them are cheap or free. We use AirMagnet and Ekahau.

If you're just looking to hunt them down one device at a time you can use the signal strength and play the old getting-hotter getting-colder game, but it's definetly not a very refined process.

If you're looking for something more comprehensive I'd suggest looking in to having a professional come in and do a site survey targeting the rogue APs. A network consultant with the right tools could quickly and easily find them and give you a report of where they are in your environment. This is a service that we provide, though our nearest office to you is near Boston.

Erik
 

Cooky

Golden Member
Apr 2, 2002
1,408
0
76
Thanks for the reply.
Which Airmagnet product do you use?

We'd pay for a consultant, except the survey he does would only be valid for the rogue devices while he's present.
I'm looking for a permanent solution that we can use from time to time.

I had Netstumbler on my laptop, and was able to isolate it to an area where I didn't see any wireless device.
Probably just something that leaked from the floor above us.
 

spidey07

No Lifer
Aug 4, 2000
65,469
5
76
If you're going the netstumbler route then get a directional antenna. There are systems out there that locate the rogue for you but they are pricey (Cisco's solution, ekahau, spectrum analyzer).
 

jlazzaro

Golden Member
May 6, 2004
1,743
0
0
i've used the Fluke OptView 3 with wireless option in the past. as spidey stated, they arent cheap...total was close to $30k. they do have other products specifically designed for wireless (fluke spectrum analyzer)

it was definately an interesting endeavour...driving in circles with a device that beeps similar to the radar used on alien
 

her209

No Lifer
Oct 11, 2000
56,336
11
0
Shut down all computers and check the switches to see which ports are still "on".
 

Cooky

Golden Member
Apr 2, 2002
1,408
0
76
What's Cisco's solution to locate rouge AP's?

I like the joke about shutting down all the computers...
 

spidey07

No Lifer
Aug 4, 2000
65,469
5
76
Their lightweight/controller based wireless uses RSSI information from mulitple access points to triangulate the rogue's position.
 

spyordie007

Diamond Member
May 28, 2001
6,229
0
0
Their lightweight/controller based wireless uses RSSI information from mulitple access points to triangulate the rogue's position.
You forgot to mention one of the best features, rogue containment (mitigation). Where your Cisco APs run a DOS against the rogue APs rendering them essentially useless.
Shut down all computers and check the switches to see which ports are still "on".
Actually that wouldn't work well, since many computers still power the NIC even when they are shut down (so the link light doesnt turn off).

Erik
 

Cooky

Golden Member
Apr 2, 2002
1,408
0
76
We're already using the LWAPP controller & AP's to triangulate the rouge.
We just need to find out exactly it is before we can legally contain it.
 

spyordie007

Diamond Member
May 28, 2001
6,229
0
0
Originally posted by: Cooky
We're already using the LWAPP controller & AP's to triangulate the rouge.
We just need to find out exactly it is before we can legally contain it.
Do you have a rogue detector setup? If there is an unencrypted rogue connected to your wired LAN the system can detect it for you.

So I have to ask, if you are already able to get their location data what is it that you are looking for? Up until now I thought you were just trying to find out where they were physically located...

:thumbsup: on the fluke
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |