Controllerless Networks

last person joined: yesterday 

Instant Mode - the controllerless Wi-Fi solution that's easy to set up, is loaded with security and smarts, and won't break your budget
Expand all | Collapse all

How to Block IP Scanners?

This thread has been viewed 5 times
  • 1.  How to Block IP Scanners?

    Posted Dec 14, 2017 06:18 AM

    Hello Everyone,

     

    I have 90 Instant 103 Access Points at the same cluster with an open SSID, any one using the IP Scanner can see every one on the network.

     

    I have tried to Enable (Deny inter user bridging) but its not working.

     

    How could i to block the ip scanners, i need to prevent any one to scan my network? How to do this at my Virtual Controller?

     

    Please help ASAP.

     

     



  • 2.  RE: How to Block IP Scanners?

    Posted Dec 18, 2017 09:44 AM

    The deny inter user bridging option should work though. Alternatively you could also work with user derivation and drop the mac-addresses from the IP scanners into another role/vlan with the necessary restrictions. 



  • 3.  RE: How to Block IP Scanners?

    Posted Dec 24, 2017 02:45 AM

    Can i apply deny inter user bridging on a cluster contains 90 AP or it works on one AP only?

    I tried to enable it on the cluster it won't work, but it works in one AP only!!!



  • 4.  RE: How to Block IP Scanners?

    EMPLOYEE
    Posted Dec 24, 2017 05:32 AM

    Derar,

     

    The problem with an open SSID is that there is nothing that really can be blocked.  A user that would have to resort to active scanning on an encrypted SSID can easily get everything they need through passtive scanning.  Unless you implement some sort of encryption on that SSID, everything can be seen..



  • 5.  RE: How to Block IP Scanners?

    Posted Dec 24, 2017 06:09 AM

    Thanks all, if i got a real controller like 72xx or 3600 could i block it there or its the same issue?



  • 6.  RE: How to Block IP Scanners?

    EMPLOYEE
    Posted Dec 24, 2017 06:30 AM

    No, you need to  start with having encryption on your SSID.  With an open ssid, everything can be seen.  With encryption it is more likely that what can and cannot be seen and can be controlled.  This is more a general statement about wireless security rather than how you keep someone from scanning your network.  Please see the document here:  https://community.arubanetworks.com/aruba/attachments/aruba/ForoenEspanol/295/1/WP_BUILDING%20GLOBAL%20SECURITY%20POLICIES%5B1%5D.pdf



  • 7.  RE: How to Block IP Scanners?

    EMPLOYEE
    Posted Dec 24, 2017 06:53 AM

    To be specific, deny inter user bridging works by blocking ARP responses.  Unless you use encryption, ARP responses would be easily seen in the air and cannot be controlled.