Instant On - Wireless

 View Only
  • 1.  APs reaching out to Russion IP addresses

    Posted 04-25-2023 01:12 AM

    On my network I block traffic to and from Russia and a few other countries. I just recently setup some new AP22s and noticed that I'm getting alerts from my firewall that they are reaching out to Russian based IP addresses. Can anyone provide insight as to what Aruba is hosting in Russia that they are reaching out to?

    2 of the IPs that I've seen are:

    109.197.199.28
    85.21.78.23

    The second IP is flagged on VirusTotal which is concerning.



  • 2.  RE: APs reaching out to Russion IP addresses

    Posted 04-26-2023 04:10 PM
    Maybe your firmware was compromised.  Where did you buy those APs?  I'd suggest resetting the firmware to factory image.






  • 3.  RE: APs reaching out to Russion IP addresses

    Posted 04-27-2023 12:31 PM

    Yeah, I'm going to try a factory reset. I haven't looked closely yet to see of its only one of the WAPs or multiple.
    I bought 5 of them through TechData/Synnex, so I'd be surprised if they are running compromised firmware.