<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: how to block WIFI network scan APP in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/how-to-block-wifi-network-scan-app/m-p/4655855#M244425</link>
    <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/979200"&gt;@W-ALI&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;&lt;SPAN&gt;The Random MAC option disabled because I enabled MAC filtering to avoid any user from register more devices&lt;/SPAN&gt;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Wut?&amp;nbsp; No.&amp;nbsp; This is wrong.&amp;nbsp;&lt;BR /&gt;Only the owner of the end devices have the "last say" on Random MAC addresses because the clients are owned by THEM (and not you).&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/979200"&gt;@W-ALI&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;&lt;SPAN&gt;so if any bad user get the real MAC by ARP , maybe can make troubles for other registered users.&lt;/SPAN&gt;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;If I turn on Random MAC addresses on my WiFi clients, no one will know but me.&amp;nbsp; No one.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;Remember, Random MAC addresses is already enabled by default.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Again, the entire issue about "stop scanning my network" is not going to work.&amp;nbsp; It is a hopeless exercise and benefits no one.&lt;/P&gt;</description>
    <pubDate>Sat, 23 Jul 2022 10:28:41 GMT</pubDate>
    <dc:creator>Leo Laohoo</dc:creator>
    <dc:date>2022-07-23T10:28:41Z</dc:date>
    <item>
      <title>how to block WIFI network scan APP</title>
      <link>https://community.cisco.com/t5/wireless/how-to-block-wifi-network-scan-app/m-p/4654934#M244367</link>
      <description>&lt;P&gt;Hello ,&lt;/P&gt;&lt;P&gt;does there any solution to prevent WIFI connected users from using any mobile applications like (Fing App) for wifi network scanner. .already I configured below ACL on WIFI connected port on switch&amp;nbsp; , but useless.&lt;/P&gt;&lt;P&gt;40 deny tcp 172.22.179.0 0.0.0.255 any eq 161&lt;BR /&gt;60 deny udp 172.22.179.0 0.0.0.255 any eq snmp&lt;BR /&gt;80 deny ip 172.22.179.0 0.0.0.255 172.22.179.0 0.0.0.255&lt;BR /&gt;100 permit ip any any&lt;/P&gt;&lt;P&gt;any solution ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jul 2022 15:05:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/how-to-block-wifi-network-scan-app/m-p/4654934#M244367</guid>
      <dc:creator>W-ALI</dc:creator>
      <dc:date>2022-07-21T15:05:43Z</dc:date>
    </item>
    <item>
      <title>Re: how to block WIFI network scan APP</title>
      <link>https://community.cisco.com/t5/wireless/how-to-block-wifi-network-scan-app/m-p/4655095#M244371</link>
      <description>&lt;P&gt;What type of WLC you get (AireOS based or IOS-XE based)? may be using AVC (Application Visibility &amp;amp; Control) feature you should be able to drop traffic from that application.&lt;/P&gt;
&lt;P&gt;HTH&lt;BR /&gt;Rasika&lt;BR /&gt;*** Pls rate all useful responses ***&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jul 2022 21:21:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/how-to-block-wifi-network-scan-app/m-p/4655095#M244371</guid>
      <dc:creator>Rasika Nayanajith</dc:creator>
      <dc:date>2022-07-21T21:21:45Z</dc:date>
    </item>
    <item>
      <title>Re: how to block WIFI network scan APP</title>
      <link>https://community.cisco.com/t5/wireless/how-to-block-wifi-network-scan-app/m-p/4655128#M244372</link>
      <description>&lt;P&gt;Hey W-AL:&lt;/P&gt;&lt;P&gt;As&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/324872"&gt;@Rasika Nayanajith&lt;/a&gt;(btw, big fan of your blog) said, It depends on what platform you are running.&lt;/P&gt;&lt;P&gt;If it is AireOS:&lt;/P&gt;&lt;P&gt;1- Create an AVC Profile under WIRELESS Tab &amp;gt; Application Visibility and Control - You can actually choose from a pretty long list of applications there and whether you want to permit or deny them.&lt;/P&gt;&lt;P&gt;2- Apply said AVC Profile to the SSID under the QoS Tab of the WLAN (or Guest LAN).&lt;/P&gt;&lt;P&gt;If running IOS-XE (i.e. 9800 WLCs): I recommend the "Understanding and Troubleshooting Cisco Catalyst 9800 Series Wireless Controllers" book (or eBook) at Ciscopress for more info.&lt;/P&gt;&lt;P&gt;1- Create a QoS Policy under Configuration &amp;gt; Services &amp;gt; QoS and choose which applications you want to block.&lt;/P&gt;&lt;P&gt;2- Once created, attach to said QoS Policy the Policy Profiles you want this QoS Policy applied to (Selected section) and the desired direction in which traffic should be blocked.&lt;/P&gt;&lt;P&gt;3- (Optional) Double check that said QoS Policy was correctly applied to the desired Policy Profile under the QoS and AVC Tab (Egress or Ingress).&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jul 2022 23:45:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/how-to-block-wifi-network-scan-app/m-p/4655128#M244372</guid>
      <dc:creator>MikeRamos</dc:creator>
      <dc:date>2022-07-21T23:45:16Z</dc:date>
    </item>
    <item>
      <title>Re: how to block WIFI network scan APP</title>
      <link>https://community.cisco.com/t5/wireless/how-to-block-wifi-network-scan-app/m-p/4655143#M244374</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1381595"&gt;@MikeRamos&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/324872"&gt;@Rasika Nayanajith&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks for your reply&lt;/P&gt;&lt;P&gt;the WLC :&amp;nbsp;&amp;nbsp; AIR-AP1815I-I-K9&amp;nbsp; and&amp;nbsp;&amp;nbsp; AIR-AP1832I-I-K9&lt;/P&gt;&lt;P&gt;please advise if that possible&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks in advance&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jul 2022 00:53:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/how-to-block-wifi-network-scan-app/m-p/4655143#M244374</guid>
      <dc:creator>W-ALI</dc:creator>
      <dc:date>2022-07-22T00:53:52Z</dc:date>
    </item>
    <item>
      <title>Re: how to block WIFI network scan APP</title>
      <link>https://community.cisco.com/t5/wireless/how-to-block-wifi-network-scan-app/m-p/4655145#M244375</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1381595"&gt;@MikeRamos&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/324872"&gt;@Rasika Nayanajith&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;as per attached Print-Screen I can't find any WIFI network Scanner Application as&lt;/P&gt;&lt;P&gt;Wireless Network watcher or Fing&lt;/P&gt;&lt;P&gt;does there any category name?&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jul 2022 01:18:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/how-to-block-wifi-network-scan-app/m-p/4655145#M244375</guid>
      <dc:creator>W-ALI</dc:creator>
      <dc:date>2022-07-22T01:18:45Z</dc:date>
    </item>
    <item>
      <title>Re: how to block WIFI network scan APP</title>
      <link>https://community.cisco.com/t5/wireless/how-to-block-wifi-network-scan-app/m-p/4655153#M244376</link>
      <description>&lt;P&gt;Hey W-AL:&lt;/P&gt;&lt;P&gt;Seems like your APs are in Autonomous Mode running Cisco Mobility Express. From your screenshot above, try looking in the networking application group (or other network-related groups) to see if you can find it there.&lt;/P&gt;&lt;P&gt;The AVC profile utilizes NBAR to recognize the traffic passing through the WLC (in your case the APs) and sometimes it has to be updated. With each update, more applications are added to the pool. Suffice to say that the newer the application you want to block is, the fewer chances you have of finding it in AireOS AVC since Cisco is moving away from that platform in favor of Catalyst 9800. I can almost guarantee you will have better chances of finding those apps in C9800.&lt;/P&gt;&lt;P&gt;Also, (and as an alternative) you can enable NBAR on your switch, provided that it can do so, and create a class-map/policy-map (Traffic Shaping) to address your issue with the unwanted traffic, however, the same idea stated above applies here: If your switch is kind of old chances are you are not going to have that app in the pool. This alternative, btw, is how you do traffic shaping in Catalyst 9800 WLCs, the only difference with a real switch is that in the 9800 you apply it to the Policy Profile.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jul 2022 01:52:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/how-to-block-wifi-network-scan-app/m-p/4655153#M244376</guid>
      <dc:creator>MikeRamos</dc:creator>
      <dc:date>2022-07-22T01:52:48Z</dc:date>
    </item>
    <item>
      <title>Re: how to block WIFI network scan APP</title>
      <link>https://community.cisco.com/t5/wireless/how-to-block-wifi-network-scan-app/m-p/4655492#M244401</link>
      <description>&lt;P&gt;I don't think&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/979200"&gt;@W-ALI&lt;/a&gt;&amp;nbsp;'s question is really about that specific app - it's about network scanning apps in general.&lt;BR /&gt;Since you're apparently using ME we assume flex mode with local switching.&lt;BR /&gt;It depends what your users need to access on the local networks but the same general principle.&lt;BR /&gt;Your ACL should deny all IP traffic to local subnets (assuming users don't need to access anything on the local subnet) eg:&lt;BR /&gt;&lt;SPAN&gt;&lt;FONT face="courier new,courier"&gt;deny ip any 172.22.179.0 0.0.0.255&lt;/FONT&gt; then permit everything else&lt;BR /&gt;&lt;/SPAN&gt;&lt;FONT face="courier new,courier"&gt;permit ip any any&lt;/FONT&gt;&lt;BR /&gt;*but* this does not prevent ARP so the scanning app can still ARP for every IP on the subnet to discover which IP addresses 'exist' but it cannot do any more than that - it can't ping or probe them.&lt;BR /&gt;You could also do a packet capture to see exactly what the app is doing and make sure the ACL covers all the possibilities.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jul 2022 13:19:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/how-to-block-wifi-network-scan-app/m-p/4655492#M244401</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2022-07-22T13:19:01Z</dc:date>
    </item>
    <item>
      <title>Re: how to block WIFI network scan APP</title>
      <link>https://community.cisco.com/t5/wireless/how-to-block-wifi-network-scan-app/m-p/4655580#M244409</link>
      <description>&lt;P&gt;Thanks &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1381595"&gt;@MikeRamos&lt;/a&gt;&amp;nbsp; for this info really appreciated,&lt;/P&gt;&lt;P&gt;the AVC profile on&amp;nbsp;AIR-AP1815 &amp;amp;&amp;nbsp;AIR-AP1832 doesn't include all APP of network scanner, however I'm seeking to find any solution to&amp;nbsp; prevent the category of network scanner APP,&lt;/P&gt;&lt;P&gt;maybe in future , must buy the new WLC technology to get the best options&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks mate for your info &amp;amp; support&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jul 2022 15:51:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/how-to-block-wifi-network-scan-app/m-p/4655580#M244409</guid>
      <dc:creator>W-ALI</dc:creator>
      <dc:date>2022-07-22T15:51:42Z</dc:date>
    </item>
    <item>
      <title>Re: how to block WIFI network scan APP</title>
      <link>https://community.cisco.com/t5/wireless/how-to-block-wifi-network-scan-app/m-p/4655583#M244410</link>
      <description>&lt;P&gt;yes &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/244975"&gt;@Rich R&lt;/a&gt; that's exactly what I mean,&lt;/P&gt;&lt;P&gt;already I did the ACL to deny Internal IPs to reach other,&lt;/P&gt;&lt;P&gt;but if any user get the ARP table , that's mean issue ,&lt;/P&gt;&lt;P&gt;because I applied &amp;amp; Enables the MAC filtering option,&amp;nbsp; that's allow to any user if get the ARP table to register other device after change the MAC by any APP.&lt;/P&gt;&lt;P&gt;I think the best practice to find any way to prevent the APP get the ARP table&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you very much for your support&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jul 2022 16:04:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/how-to-block-wifi-network-scan-app/m-p/4655583#M244410</guid>
      <dc:creator>W-ALI</dc:creator>
      <dc:date>2022-07-22T16:04:20Z</dc:date>
    </item>
    <item>
      <title>Re: how to block WIFI network scan APP</title>
      <link>https://community.cisco.com/t5/wireless/how-to-block-wifi-network-scan-app/m-p/4655585#M244411</link>
      <description>&lt;P&gt;It is my absolute pleasure,&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/979200"&gt;@W-ALI&lt;/a&gt;&amp;nbsp;!&lt;/P&gt;&lt;P&gt;Yeah I figured you wanted to do more like an application group type of blocking instead of an specific app. The C9800 does a tremendous job at that and has quite a lot of apps in NBAR. You can also achieve this if you have Catalyst 9Ks switches so the QoS Traffic Shaping will then happen at the switch level instead of the WLC one since they run the same NBAR packages.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jul 2022 16:10:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/how-to-block-wifi-network-scan-app/m-p/4655585#M244411</guid>
      <dc:creator>MikeRamos</dc:creator>
      <dc:date>2022-07-22T16:10:19Z</dc:date>
    </item>
    <item>
      <title>Re: how to block WIFI network scan APP</title>
      <link>https://community.cisco.com/t5/wireless/how-to-block-wifi-network-scan-app/m-p/4655597#M244412</link>
      <description>&lt;P&gt;I'm not sure there is any easy way to block the ARP but we've never really tried and I don't think NBAR will be able to it either.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jul 2022 16:29:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/how-to-block-wifi-network-scan-app/m-p/4655597#M244412</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2022-07-22T16:29:08Z</dc:date>
    </item>
    <item>
      <title>Re: how to block WIFI network scan APP</title>
      <link>https://community.cisco.com/t5/wireless/how-to-block-wifi-network-scan-app/m-p/4655742#M244419</link>
      <description>&lt;P&gt;Wait, this is all wrong.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;@&lt;A id="inResponseTo_3" class="lia-link-navigation lia-message-reply-in-response-to" href="https://community.cisco.com/t5/wireless/how-to-block-wifi-network-scan-app/m-p/4655583/highlight/true#M244410" target="_blank"&gt;&lt;SPAN class="lia-message-in-response-to-username"&gt;W-ALI&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;wants to block users from using an IP scanner and discover the MAC addresses.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;No one can stop anyone from using an app.&amp;nbsp; No one.&amp;nbsp; And, equally, no one can say, "do not scan our network" unless someone really wants to court trouble.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyone, however, can minimize the scope of the scan by segmenting the network with VRF or a firewall.&amp;nbsp; The firewall, can say, "if you are in the public WiFi subnet, you cannot go anywhere else but the internet".&amp;nbsp; That means, public WiFi users have no access to corporate subnet.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So it will definitely not help if the public WiFi subnet and the corporate subnet is the same or one big 10.0.0.0/8 subnet.&amp;nbsp; Now that, is really asking for trouble.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Next, does anyone know what the implication is if someone decides to unitarily block ICMP echo from the network?&amp;nbsp; I do.&amp;nbsp; Things break.&amp;nbsp; Internet of Trash with poorly written code will stop working if ICMP echo response is disabled or blocked.&lt;/P&gt;
&lt;P&gt;Finally, does it make any difference what is found?&amp;nbsp; Random MAC address is enabled by default.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 23 Jul 2022 01:12:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/how-to-block-wifi-network-scan-app/m-p/4655742#M244419</guid>
      <dc:creator>Leo Laohoo</dc:creator>
      <dc:date>2022-07-23T01:12:57Z</dc:date>
    </item>
    <item>
      <title>Re: how to block WIFI network scan APP</title>
      <link>https://community.cisco.com/t5/wireless/how-to-block-wifi-network-scan-app/m-p/4655854#M244424</link>
      <description>&lt;P&gt;Thanks &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326026"&gt;@Leo Laohoo&lt;/a&gt; for your great input&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;I would like to clarify more&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;the WIFI VLAN created on Firewall with below ACL:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;permit to some internal server IPs by ports&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;deny to&amp;nbsp; private network (192.168.XX ,10.X.X.X , 172.16.0.0-172.31. 255.255)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;permit to any&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;also I created the below ACL on Switch&amp;nbsp; port connected to WIFI&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;40 deny tcp 172.22.179.0 0.0.0.255 any eq 161&lt;BR /&gt;45 deny icmp 172.22.179.0 0.0.0.255 any echo&lt;BR /&gt;60 deny udp 172.22.179.0 0.0.0.255 any eq snmp&lt;BR /&gt;80 deny ip 172.22.179.0 0.0.0.255 172.22.179.0 0.0.0.255&lt;BR /&gt;100 permit ip any any (28008 matches)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;The Random MAC option disabled because I enabled MAC filtering to avoid any user from register more devices ,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;so if any bad user get the real MAC by ARP , maybe can make troubles for other registered users.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;so I'm trying to find any solution to prevent that.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 23 Jul 2022 10:16:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/how-to-block-wifi-network-scan-app/m-p/4655854#M244424</guid>
      <dc:creator>W-ALI</dc:creator>
      <dc:date>2022-07-23T10:16:01Z</dc:date>
    </item>
    <item>
      <title>Re: how to block WIFI network scan APP</title>
      <link>https://community.cisco.com/t5/wireless/how-to-block-wifi-network-scan-app/m-p/4655855#M244425</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/979200"&gt;@W-ALI&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;&lt;SPAN&gt;The Random MAC option disabled because I enabled MAC filtering to avoid any user from register more devices&lt;/SPAN&gt;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Wut?&amp;nbsp; No.&amp;nbsp; This is wrong.&amp;nbsp;&lt;BR /&gt;Only the owner of the end devices have the "last say" on Random MAC addresses because the clients are owned by THEM (and not you).&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/979200"&gt;@W-ALI&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;&lt;SPAN&gt;so if any bad user get the real MAC by ARP , maybe can make troubles for other registered users.&lt;/SPAN&gt;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;If I turn on Random MAC addresses on my WiFi clients, no one will know but me.&amp;nbsp; No one.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;Remember, Random MAC addresses is already enabled by default.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Again, the entire issue about "stop scanning my network" is not going to work.&amp;nbsp; It is a hopeless exercise and benefits no one.&lt;/P&gt;</description>
      <pubDate>Sat, 23 Jul 2022 10:28:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/how-to-block-wifi-network-scan-app/m-p/4655855#M244425</guid>
      <dc:creator>Leo Laohoo</dc:creator>
      <dc:date>2022-07-23T10:28:41Z</dc:date>
    </item>
    <item>
      <title>Re: how to block WIFI network scan APP</title>
      <link>https://community.cisco.com/t5/wireless/how-to-block-wifi-network-scan-app/m-p/4655865#M244426</link>
      <description>&lt;P&gt;thanks &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326026"&gt;@Leo Laohoo&lt;/a&gt;&amp;nbsp; for your reply and notes&lt;/P&gt;&lt;P&gt;we forced the WiFi users to disable random mac option and provide me with the real MAC device to add it in white list because I enabled the MAC filtering so if&amp;nbsp; enable random mac will failed login&lt;/P&gt;&lt;P&gt;the purpose of whitelisted MAC ,&amp;nbsp; to prevent users from add any other device because already he had the SSID password,&lt;/P&gt;&lt;P&gt;however in the past I enabled the 802.1X login by domain user &amp;amp; password , but I cant found any way to allow just concurrent session, the users was login from laptops and also the Mobile because I have no Captive portal to allow just concurrent login,&lt;/P&gt;&lt;P&gt;so for that I disabled 802.1X and allowed the MAC filtering.&lt;/P&gt;&lt;P&gt;I'm just looking for the best practice to secure the WIFI w&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;ith the capabilities currently available.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 23 Jul 2022 11:56:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/how-to-block-wifi-network-scan-app/m-p/4655865#M244426</guid>
      <dc:creator>W-ALI</dc:creator>
      <dc:date>2022-07-23T11:56:23Z</dc:date>
    </item>
    <item>
      <title>Re: how to block WIFI network scan APP</title>
      <link>https://community.cisco.com/t5/wireless/how-to-block-wifi-network-scan-app/m-p/4655867#M244427</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/979200"&gt;@W-ALI&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;&lt;SPAN&gt;I'm just looking for the best practice to secure the WIFI w&lt;/SPAN&gt;&lt;SPAN class=""&gt;ith the capabilities currently available.&lt;/SPAN&gt;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;802.1x&lt;/P&gt;</description>
      <pubDate>Sat, 23 Jul 2022 12:10:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/how-to-block-wifi-network-scan-app/m-p/4655867#M244427</guid>
      <dc:creator>Leo Laohoo</dc:creator>
      <dc:date>2022-07-23T12:10:48Z</dc:date>
    </item>
    <item>
      <title>Re: how to block WIFI network scan APP</title>
      <link>https://community.cisco.com/t5/wireless/how-to-block-wifi-network-scan-app/m-p/4656724#M244462</link>
      <description>&lt;P&gt;Regarding MAC filtering. With a normal wireless sniffer, that can be installed on any laptop, for example Wireshark, you can simply capture a bit in promiscuous mode and you get all the client MAC addresses in the captured data. MAC addresses are no secret, they are more or less public.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Because of that your best option is to use 802.1x with a Radius server that can limit the simultaneous logins per username/certificate to 1.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But in the end I wouldn't do this, as more and more devices will want Wi-Fi. It's very soon that every user has a tablet, laptop, smart watch, .... which should be online.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jul 2022 11:22:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/how-to-block-wifi-network-scan-app/m-p/4656724#M244462</guid>
      <dc:creator>patoberli</dc:creator>
      <dc:date>2022-07-25T11:22:19Z</dc:date>
    </item>
    <item>
      <title>Re: how to block WIFI network scan APP</title>
      <link>https://community.cisco.com/t5/wireless/how-to-block-wifi-network-scan-app/m-p/4656783#M244465</link>
      <description>&lt;P&gt;Agreed with&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/323352"&gt;@patoberli&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jul 2022 11:48:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/how-to-block-wifi-network-scan-app/m-p/4656783#M244465</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2022-07-25T11:48:57Z</dc:date>
    </item>
    <item>
      <title>Re: how to block WIFI network scan APP</title>
      <link>https://community.cisco.com/t5/wireless/how-to-block-wifi-network-scan-app/m-p/4656793#M244466</link>
      <description>&lt;P&gt;Thanks a lot&amp;nbsp; &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/323352"&gt;@patoberli&lt;/a&gt; for your input, really appreciated that,&lt;/P&gt;&lt;P&gt;yes that's true&lt;/P&gt;&lt;P&gt;the best solution 802.1X&amp;nbsp; , i will try to apply it with certificate&lt;/P&gt;&lt;P&gt;thanks mate&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jul 2022 11:57:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/how-to-block-wifi-network-scan-app/m-p/4656793#M244466</guid>
      <dc:creator>W-ALI</dc:creator>
      <dc:date>2022-07-25T11:57:53Z</dc:date>
    </item>
  </channel>
</rss>

