<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Unknown device in wireless client list but no IP address assigned.</title><link>https://community.sophos.com/utm-firewall/f/wireless-security/102711/unknown-device-in-wireless-client-list-but-no-ip-address-assigned</link><description>Becoming more familiar with the UTM I am making an effort to check my logs for suspicious activity. I have been keeping an eye on my wireless protection logs and I am noticing something suspicious. an unknown wireless device has been attempting to connect</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: Unknown device in wireless client list but no IP address assigned.</title><link>https://community.sophos.com/thread/373571?ContentTypeID=1</link><pubDate>Wed, 16 May 2018 17:12:24 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:5400bfad-1220-40a7-903d-ddc091522eb4</guid><dc:creator>alan weir</dc:creator><description>&lt;p&gt;No as I&amp;nbsp;have not given my passcode to anyone. I am the only one that uses this wireless connection. Probably a neighbor is attempting to access this connection. With that being said I still don&amp;#39;t understand how the device was able to show up in my wireless client access list without a successful association.&amp;nbsp;Does any client that attempts to connect show up in this list and should I be concerned that the log shows the device was authenticated?&lt;/p&gt;
&lt;p&gt;The status code &amp;quot;0&amp;quot; in the log, according to Intel, suggests that the association was successful, then a few seconds later there is a STA WPA failure. As I said before, there is no record of this wireless client receiving an IP address in the DHCP log.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;After changing my wifi password I have not seen any more connection attempts but I have taken the following steps.&lt;/p&gt;
&lt;p&gt;Created a MAC address definition for the unknown device&lt;/p&gt;
&lt;p&gt;Created a network definition based on that MAC address and gave it an IP address on a different subnet.&lt;/p&gt;
&lt;p&gt;Created&amp;nbsp;two&amp;nbsp;firewall rules blocking any source&amp;nbsp;and any service to that IP address, and blocking that IP address to any destination using any service.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.intel.com/content/www/us/en/support/articles/000006508/network-and-i-o/wireless-networking.html"&gt;https://www.intel.com/content/www/us/en/support/articles/000006508/network-and-i-o/wireless-networking.html&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Association&lt;/strong&gt;&lt;br /&gt;Once authentication is complete, mobile devices can associate (register) with an AP/router to gain full access to the network. Association allows the AP/router to record each mobile device so that frames are properly delivered. Association only occurs on wireless infrastructure networks, not in peer-peer mode. A station can only associate with one AP/router at a time.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Association process:&lt;/strong&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Mobile device authenticates to an AP/router and then sends an Association Request.&lt;/li&gt;
&lt;li&gt;AP/router processes the Association Request. AP/router vendors may have different implementations for deciding if a client request should be allowed.
&lt;ul&gt;
&lt;li&gt;When an AP/router grants association, it responds with a status code of 0 (successful) and the Association ID (AID). The AID is used to identify the station for delivery of buffered frames when power-saving is enabled.&lt;/li&gt;
&lt;li&gt;Failed Association Requests include only a status code and the procedure ends.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;AP/router forwards frames to or from the mobile device.&lt;/li&gt;
&lt;/ol&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Unknown device in wireless client list but no IP address assigned.</title><link>https://community.sophos.com/thread/373564?ContentTypeID=1</link><pubDate>Wed, 16 May 2018 15:23:00 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:de4649d3-fec7-44aa-80f9-74900cdd3d0e</guid><dc:creator>BAlfson</dc:creator><description>&lt;p&gt;Alan, could that be a colleague&amp;#39;s LG cell phone that doesn&amp;#39;t have the passcode entered correctly??&lt;/p&gt;
&lt;p&gt;Cheers - Bob&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Unknown wireless client keeps associating/authenticating/deauthenticating all day long. Authentication but no IP address given.</title><link>https://community.sophos.com/thread/373398?ContentTypeID=1</link><pubDate>Tue, 15 May 2018 16:54:14 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:7800247c-b8e4-402b-aed7-429349db03c9</guid><dc:creator>alan weir</dc:creator><description>&lt;p&gt;Not to bump my own thread, but it just&amp;nbsp;happened again. I cannot figure out what this LG device is or&amp;nbsp;how it is connecting. Could there be malware on my device that is changing the MAC address of the phone and then connecting on top of the wifi connection I already have? Surely there must be some explanation. The unknown MAC address is in the red square.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;a href="/cfs-file/__key/communityserver-discussions-components-files/60/7536.wireless3.jpg"&gt;&lt;img src="/resized-image/__size/1200x800/__key/communityserver-discussions-components-files/60/7536.wireless3.jpg" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;I also notice that anytime I make changes to the wireless network&amp;nbsp;settings, I will receive an authentication error and I will have to re-enter my wifi password into the UTM or I will never be able to connect.&lt;/p&gt;
&lt;p&gt;For the meantime I created a MAC address definition (for my Samsung) and added my phone to the whitelist using the whitelist filtering in the wireless network settings. Now I will see if that rogue MAC address show up again.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>