Recommended Posts

So lately we have been having an issue with people viewing adult content at work.

Basically someone comes in and forgets they are on the company wireless and goes to find a site o' fun on their mobile device.

Until recently, I've been able to track down who it was. But now default device naming conventions prevent that. Android_longassstring doesn't help me.

All I know is it is 192.168.100.18.

Two questions:

1. How can I block this IP from accessing the internet while it has a DHCP lease.

2. Any other ways of tracking down the idiot?

Thanks.

Link to comment
https://www.neowin.net/forum/topic/1103809-block-internal-ip/
Share on other sites

What do you have in place at work for your router/firewall? How are you seeing where the people are going? Many proxies have a way of filtering.

Give me some details of what your working with for infrastructure and or budget and we can work out the best way to filter using what you have or that will fit into your budget. I can not believe a place of business does not filter internet traffic? You can do some amazing things on really 0 budget, if you have some hardware to work with and some time for setup.

As to tracking down a wireless client - yeah that can be very difficult. You could implement login to access your wireless via your AD/LDAP, etc You could setup a captive portal sort of thing even if you just allow open wireless connectivity.

There are lots and lots of options here - just need to know what your working with, and what you might be able to add to your network.

Off the cuff, some random mobile device its going to be impossible to track - simple thing would be to block his mac from getting an IP of said device... Or just setup a reservation for his mac so that he gets same IP you block at your firewall from getting to the internet. If you know his IP, you know his mac - if you know his mac you can setup a reservation so he always gets the same IP, once you know that device will always get the same IP, you can block that IP from accessing the internet. Or depending on your setup block from even getting an IP, etc.

Love to help you fix up your network so you can filter and monitor users internet traffic - just need somewhere to start, ie what do you have to work with.

Pretty simple setup -

Server -> Sonicwall w/ 2 switches and an AP -> ISP -> OpenDNS

So if content manages to get by the Sonicwall, it happens - hits OpenDNS and gets stopped.

We have the filtering in place, that's not the issue. It's finding out who attempted to access these sites.

So I know the IP because of DHCP, how can I pull the MAC ID and block that? Can I block it in DHCP?

Why allow phones to access the network anyway? Why. It throw in a content manager other than opendns. Something that can manage it better? Or have open dns integrate with ad so it requires ad auth. The auth, it creates a log of who and what the accessed. No need to hunt crap down, you know who did it based on user account.

"hits OpenDNS and gets stopped."

What?? Sorry opendns is provider of dns, it does not stop anything. You ask it for stuff like www.neowin.net or www.playboy.com, etc. and then it either returns the correct IP for you to go there, or it sends you its IP so you end up on some block page. It does not actually filter traffic, unless they have recently added proxy support?

So do you block 53 outbound to everything else other then the opendns servers? If not circumvention of your opendns filtering there any 6 year old could bypass ;) What sonicwall do you have? They provide web content filtering services - you just have to be licensed for them.

You could tie to opendns enterprise insight, sure this ties it to your AD -- I don't believe its very cost friendly?? And unless your blocking outbound udp/tcp 53 anyone can bypass it really easy.

What AP do you have? Does it tie in with your sonicwall? Model numbers of your devices would be very helpful so we know exactly what we are dealing with. But you have a sonicwall, which sc302 I believe has more exp with than me. But clearly they can block who you want, and if your AP is tied in with it you can require AD to auth to even get on your wireless.

What?? Sorry opendns is provider of dns, it does not stop anything.

OpenDNS has a content filter that sometimes does better than the Sonicwall. That's what I meant about content getting stopped.

We have a Sonicwall TZ210, Cisco Aironet 1040 AP.

OpenDNS is too pricey for my budget (non profit organization) even with their "discounts".

I would imagine that either the Sonicwall or the Cisco device could tie in to AD but I've never done that before.

@sc302 - wireless is a "perk" I guess. But it's also needed so people can do their jobs and I'm not sure how much work it is to lock it all down to only X devices.

The sonic wall appliance has a purchasable subscription package for content filtering that does a pretty good job and should be the same or better than opendns. With this, it should also tie into ad to be able to give you reports based on user. If you don't sign in with an ad account, you don't get access. Turn off anonymous access.

Well if you want to know who is going where, I would connect both of them to AD. I would require auth to get on your wireless. So its just completely open now, or you have just a PSK setup?

So do you control your AP from the sonicwall or is it standalone? You don't have a cisco wireless controller for 1 AP that is for sure. But the TZ210 can handle up to 16 sonicpoints, or AP ;)

So you do content filtering now on the sonicwall, but you don't set policy based upon AD users?

But still a bit hazy on even your original question - if your doing content filtering at the sonicwall, and you notice someone going to site X, just block site X at the sonicwall. You don't really have to know who is going there to prevent them from going. Content filtering at sonicwall clearly has ability to whitelist/blacklist urls, ie custom filtering of sites.

So do you control your AP on the sonicwall, or standalone? Either way can show you how to point to your AD. What AD do you have setup? NT, 2k, 2k3, 2k8? Or you just running LDAP on some linux box?

I would do AD auth requirements, RADIUS or is it called 802.x EAP?. I was working at the City Hall for a few weeks last year and they set it up to use 802.1x EAP - which then required me to also put in my username/password. That would definitely lead back to me if I was browsing anything wrong even on my mobile phone :)

regardless, it still goes through the sw does it not? if you set it up where users need to auth to access the web, regardless of whether or not they are on the domain, you would easily be able to determine who is going where.

for example, when I am on my ad computer I can go out to the web where I am allowed and if I am on my phone I need to auth with my ad creds to get out to the web where I am allowed. In either case, they know where I am going and how long I have been there, or if I access a questionable site.

regardless, it still goes through the sw does it not? if you set it up where users need to auth to access the web, regardless of whether or not they are on the domain, you would easily be able to determine who is going where.

for example, when I am on my ad computer I can go out to the web where I am allowed and if I am on my phone I need to auth with my ad creds to get out to the web where I am allowed. In either case, they know where I am going and how long I have been there, or if I access a questionable site.

Yeah the AP goes through the Sonicwall. I don't know where I should setup the auth tho, I'd imagine I'd do that at the AP. Would it be better on the Sonicwall? Never done either...would love it to associate with LDAP though.

I don't know how Things work were you live(laws and such), but you should be aware of something called privacy. In Norway we're pretty strict about privacy. You should NEVER log computer usage like web traffic that can identify the user(without approval from the employees). If you Discover that employees often tries to Access blocked content, the right thing to do would be to: 1. Block Access(ex. using Your SW's content filtering). And 2. Send an email to ALL employees reminding them of the company's IT-policy, including accessing non-workrelated websites(or whatever you policy is).

@Graimer, yeah there is a huge difference between US law and say Norway for privacy.

So after you send out 140th mass email saying stay off the porn what happens? Do you finally track down the user and say Quit it?? ;)

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Amazon Prime Day 2026: Best Dolby soundbar deals from Sony, Samsung, JBL, Polk, and more by Sayan Sen Yesterday we covered the JBL BAR 800 which is a 5.1.2 Dolby Atmos/Vision soundbar. The unit is on sale for its lowest ever price of just $800 making it a solid offer. However, there are many more options to choose from and in this article, we have made a compilation of the best deals including from Sony, Polk, Yamaha, Denon, Samsung and more. Sony's BAR models are currently at their lowest prices which makes them solid offerings. The company's BRAVIA Theatre Bar lineup is designed to suit different home cinema needs. The Bar 5 is an entry-level 3.1-channel soundbar with a wireless subwoofer, supporting Dolby Atmos®, DTS:X, S-Force PRO Front Surround, and Vertical Surround Engine for immersive audio with clear dialogue. The Bar 6 upgrades to a 3.1.2-channel configuration by adding dedicated up-firing speakers for more convincing overhead Atmos effects while retaining the wireless subwoofer. At the premium end, the Bar 7, Bar 8, and flagship Bar 9 are single-soundbar solutions featuring Sony’s 360 Spatial Sound Mapping technology, which creates phantom speakers for a wider surround field. Bar 7 includes nine speaker units, Bar 8 increases this to eleven, and Bar 9 offers thirteen speaker driver units promising the most expansive soundstage and acoustic performance. All models should integrate seamlessly with compatible BRAVIA TVs and support the BRAVIA Connect app for setup and control. Get them at the links below: Sony BRAVIA Theater Bar 9 Soundbar (HT-A9000): $998.00 (Amazon US) (Was: $1498) Sony BRAVIA Theater Bar 8 Soundbar (HT-A9000): $798.00 (Amazon US) (Was: $998) Sony BRAVIA Theater Bar 7 Soundbar (HT-A7100): $618.00 (Amazon US) (Was: $768) Sony BRAVIA Theater System 6: $548.00 | Sony BRAVIA Theater Bar 6: $448.00 Sony BRAVIA Theater Bar 5 (HT-B500): $278.00 (Amazon US) (Was: $348) Sony HT-S400 2.1 soundbar: $198.00 (Amazon US) (Was: $248) Aside from those, we also have more discounts including from Samsung, Polk Audio, and more: Samsung Q-Series Soundbar HW-QS90H 7.1.2: $797.99 (Amazon US) (Was: $998) Polk Audio Signa S4: $336.00 (Amazon US) (Was: $449) Hisense AX3120Q: $229.00 (Amazon US) (Was: $259) Check out more soundbar deals that you may like at this link. Good to know This Amazon deal is U.S. specific, and not available in other regions unless specified. We only use first-party seller links (at the time of article publishing); ensure that you purchase from a first-party seller link only. Check out Today's Deals on Amazon | or our recent tech deals. Become a Prime member (for Students or SNAP) via Neowin Get Prime Access - Prime for half price (for qualifying Medicaid, EBT, SNAP) Subscribe to Prime Video, Audible Plus, Music Unlimited or Kindle Unlimited via Neowin As an Amazon Associate, we earn from qualifying purchases.
    • Stellarium 26.2 by Razvan Serea Stellarium is a free open source planetarium for your computer. It shows a realistic sky in 3D, just like what you see with the naked eye, binoculars or a telescope. It is being used in planetarium projectors. Just set your coordinates and go. Stellarium key features: Realistic simulation of the sky, sunrise and sunset Default catalogue of over 600,000 stars Downloadable additional catalogues for up to 210 million stars Catalog data for all New General Catalogue (NGC) objects Images of almost all Messier objects and the Milky Way Artistic illustrations for all 88 modern constellations More than a dozen different cultures with their constellations Solar and lunar eclipse simulation Photorealistic landscapes (more are available on the website) Scripting support with ECMAScript (a few demo scripts are included) Extendable with plug-ins: 8 plug-ins installed by default, including: artificial satellites plug-in (updated from an on-line TLE database) ocular simulation plug-in (shows how objects look like in a given ocular) Solar System editor plug-in (imports comet and asteroid data from the MPC) telescope control plug-in (Meade LX200 and Celestron NexStar compatible) The major changes of this version: Added new sky culture Added new plugin: Planes Many improvements in plugins Many improvements in Core and GUI Many updates in sky cultures. [full release notes] Download: Stellarium 26.2 (64-bit) | 456.0 MB (Open Source) View: Stellarium Home Page | Other Operating Systems | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • NASA: This asteroid may not kill us but it probably won't be far off either by Sayan Sen Image by Zelch Csaba via Pexels New observations by NASA's James Webb Space Telescope have eliminated the last remaining impact threat posed by asteroid 2024 YR4, ruling out the possibility that the near-Earth object could strike the Moon in December 2032. NASA said observations collected by Webb on February 18 and 26, 2026, enabled scientists to refine the asteroid's orbit enough to "rule out a chance of lunar impact on Dec. 22, 2032." Instead, asteroid 2024 YR4 is now expected to pass the Moon at a distance of about 13,200 miles (21,200 km). The agency stressed that the update "reflects improved precision in our understanding of where the asteroid is expected to be in 2032 rather than a shift in its orbital path." The announcement closes a remarkable chapter in planetary defence that began in late 2024, when the approximately 60-metre-wide asteroid briefly became the most closely watched near-Earth object in the world. Discovered on December 27, 2024, by the ATLAS telescope in Chile, 2024 YR4 initially appeared to have a small chance of colliding with Earth on December 22, 2032. As astronomers gathered more observations, the impact probability briefly climbed to around 3%—the highest ever recorded for an asteroid of its size—before steadily falling as its orbit became better understood. By early 2025, international observations had ruled out any significant risk to Earth. However, astronomers were left with another possibility: a roughly 4% chance that the asteroid could instead strike the Moon. "The probability that asteroid 2024 YR4 will strike the Moon on 22 December 2032 is now approximately 4%," the European Space Agency (ESA) had said last year, noting that "there is a 96% chance that the asteroid will not impact the Moon." ESA said such an impact, while unlikely, would have presented an extraordinary scientific opportunity. "It is a very rare event for an asteroid this large to impact the Moon – and it is rarer still that we know about it in advance. The impact would likely be visible from Earth, and so scientists will be very excited by the prospect of observing and analysing it," said Richard Moissl, Head of ESA's Planetary Defence Office. "It would certainly leave a new crater on the surface. However, we wouldn't be able to accurately predict in advance how much material would be thrown into space, or whether any would reach Earth," he added. The asteroid also exposed an important blind spot in planetary defence. Because 2024 YR4 approached Earth from the direction of the Sun, it remained hidden from ground-based telescopes until after its closest approach. "We looked into how Neomir would have performed in this situation, and the simulations surprised even us," Moissl said. "Neomir would have detected asteroid 2024 YR4 about a month earlier than ground-based telescopes did. This would have given astronomers more time to study the asteroid's trajectory and allowed them to much sooner rule out any chance of Earth impact in 2032." He added, "As an infrared telescope, like Webb, Neomir would have also immediately given us a much better estimate for the asteroid's size, which is very important for assessing the significance of the hazard." The latest NASA observations underscore the value of space-based infrared telescopes in tracking faint asteroids. According to NASA, Webb made "among the faintest ever observations of an asteroid," extending the object's observational record by nearly eight months at a time when it had become too faint for other telescopes. That additional data allowed scientists to eliminate the remaining uncertainty surrounding its 2032 flyby. Although asteroid 2024 YR4 is now confirmed to pose no threat to either Earth or the Moon, scientists say its discovery remains one of the most significant real-world tests of the international planetary defence system, demonstrating how continued observations can rapidly transform an object once considered hazardous into one whose future path is known with high confidence. Source: NASA, ESA This article was generated with some help from AI and reviewed by an editor. Under Section 107 of the Copyright Act 1976, this material is used for the purpose of news reporting. Fair use is a use permitted by copyright statute that might otherwise be infringing.
  • Recent Achievements

    • Conversation Starter
      Admir earned a badge
      Conversation Starter
    • First Post
      The_Focal_Point earned a badge
      First Post
    • Apprentice
      daryld went up a rank
      Apprentice
    • Contributor
      Carltonbar went up a rank
      Contributor
    • One Month Later
      The_Focal_Point earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      418
    2. 2
      +Edouard
      170
    3. 3
      PsYcHoKiLLa
      130
    4. 4
      Xenon
      69
    5. 5
      neufuse
      69
  • Tell a friend

    Love Neowin? Tell a friend!