I have a mystery device that is detected on my network. It seems to come online then go offline now and then. It seems to be smart, because when I placed a Geo based policy to US_Geo it seemed to switch to only US based IP's.
I have literally disconnected all devices on my network and it still appears online with everything offline.
I looked at my arp table...
W80CM# get sys arp Address Age(min) Hardware Addr Interface 192.168.1.100 0 mac here lan 192.168.1.101 0 mac here lan 192.168.1.150 0 mac here lan 192.168.1.151 0 mac here lan 192.168.1.152 0 mac here lan 192.168.1.220 0 mac here lan My.ISP.IP.Here (the real one) 0 mac here wan1
It seems to be using my WAN mac address.
The mystery device in User & Device > Device>Device Definitions
Offline IPhere UnknownDevice Linux / 2.6 UnknownDevice 21:29:38 mac_here Cisco Systems, Inc
Its a 212.x.x.x as of right now, this changes often. This is not my IP. These addresses changed to US based addresses while I had the US_Geo Policy enabled. I since had to remove this policy for administration reasons.
Firmware Versionv5.2.6,build711 (GA)
Fortigate 80CM
Any ideas? I literally took all devices offline but the Fortigate and the ISP Modem, and this device still appeared online. Is it detecting my ISP hardware? Why would the IP change all over the Globe constantly?
add-in: Not my Modem.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
To follow up and edit info - this was an infection in my LAN. I redid a laptop and it went away.
-No WAN detection was no enabled.
Yeah, I have seen that happen on a few clients networks. It drove me up the wall at first as well!
Mike Pruett
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1712 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.