11-13-2023 07:34 AM
Last week all of a sudden, I'm starting to see teacher laptops show up under Rogue SSID contained, all start with "direct". with the "seen on lan" message. I am whitelisting them as they come in but wonder why this started happening, Happening with the old and new firmware. No blocked rules in place and they are on wireless only, no wired connection also in use.
I ran across an old thread mentioning screen mirroring and false positives. Most machines do run Air Server to project their ipads through the laptop then projector. I can troubleshoot that by disabling air server on a few machines with the issue but we still need to use it. What seems to be happening when it captured by air marshall, it deauthenticates the user and makes them log back into our wifi.
Any ideas or suggestions? Thanks.
11-13-2023 08:06 AM
11-13-2023 08:15 AM
Block clients from connecting to rogue SSIDs by default
Nothing in the blocklist, do have items whitelisted
11-13-2023 08:27 AM
Care should be taken when configuring SSID block list policies as these policies will apply to SSIDs seen on the LAN as well as off of the LAN from neighboring WiFi deployments. Containment can have legal implications when launched against neighbor networks, and it may harm your own network by increasing channel utilization and potential disrupt clients connecting to your APs. Ensure that the rogue device is within your network and poses a security risk before you launch the containment.
Review the section Overview of Air Marshal Containment to understand how the APs may block the configured SSIDs.
11-13-2023 08:31 AM
I don't have anything in the block list, no block rules. Not containing anything.
11-13-2023 08:35 AM
You said it's blocking by default, change it to allow to see if the problem continues.
11-13-2023 08:48 AM
I've done that, but I don't want to leave it that way. I would like to use air marshal. Even meraki documentation was using that option give you a more secure network when set to block. I want to know why its all of a sudden containing teacher laptops? Never has in the past. They dont have a ssid that can be spoofed. I am assuming its because they are broadcasting air server connections. But that has never been an issue either until now.
11-13-2023 08:50 AM
11-13-2023 09:00 AM
Here is an example:
11-13-2023 08:59 AM
Why is meraki saying different? Its literally on the Air Marshall page
"Your Meraki access points will block clients from connecting to all rogue SSIDs by default. This setting is appropriate when you have all Meraki access points at your site and is better for security. You can allow connections to individual SSIDs by using the Allow list below."
I am all meraki other than two aps we use for other stuff and they are whitelisted.
11-13-2023 09:02 AM
Containment can have legal implications when launched against neighbor networks, and it may harm your own network by increasing channel utilization and potential disrupt clients connecting to your APs. Ensure that the rogue device is within your network and poses a security risk before you launch the containment.
But you can do whatever you want, my advice is still: don't do it.
11-13-2023 09:04 AM
You arent reading my posts, you are just copying and pasting stuff.
Why are my teacher machines all of a sudden being caught by air marshall? That's what we need to fix.
11-13-2023 09:06 AM
11-13-2023 09:06 AM
This setting is appropriate when you have all Meraki access points at your site and is better for security.
So Meraki is wrong with this statement?
11-13-2023 09:09 AM
It's neither right nor wrong. I just think you shouldn't blindly trust everything you read in the documentation.
Air Marshal is an excellent tool, but sometimes it can have unexpected behaviors, hence my suggestion to create specific rules.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide