Monday, December 4, 2017

Mitigate Cisco/Meraki Clean Air / Air Marshall?

This is an oddball request, but I'm at a loss here. It's for my personal home, but this is all involving enterprise grade equip and is over the heads of the homenetworking forum. I have two UBNT AP's that suddenly stopped working on Friday. Associations all time out, and if they do manage to associate, the client drops within a minute or less.

I didn't have any tools with me beyond access to the controller, Wireshark, and istumbler on my mac. Doing wireshark packet captures, I can see the association request, keying, and association, immediately followed by several deauths "from my AP"

Istumbler was interesting, because I saw a new SSID I've never seen before, and it's using Cisco/Meraki equipment. Also the signal is so good they could be right on top of me.

I am putting two and two together, but I think that the deauths are being forged by this new meraki because that's how Cisco Clean air and Meraki Air Marshall work.

I've already played the whole upgrade/downgrade, reinstall game with my UBNT and brought one to work with me this morning and found it works just fine here.

Besides being able to take my fluke home this evening to find where it is, how can I mitigate it if I think who it could be is a total D.Bag and probably won't fix it? FCC? Even though I know they won't follow through.



No comments:

Post a Comment