<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: R320 started making requests to international endpoint in Unleashed</title>
    <link>https://community.ruckuswireless.com/t5/Unleashed/R320-started-making-requests-to-international-endpoint/m-p/54756#M4916</link>
    <description>&lt;P&gt;I understand that the CNA URL will be accessed. And it would make sense if my router was reporting that my mobile devices were accessing it, but the source of the connections are the master AP's MAC address. That's what is confusing me.&lt;/P&gt;&lt;P&gt;I did perform a capture per your instructions but I'm having trouble interpreting. I'll see if I can get help via support ticket, thanks for your time.&lt;/P&gt;</description>
    <pubDate>Wed, 08 Mar 2023 06:14:44 GMT</pubDate>
    <dc:creator>defect</dc:creator>
    <dc:date>2023-03-08T06:14:44Z</dc:date>
    <item>
      <title>R320 started making requests to international endpoint</title>
      <link>https://community.ruckuswireless.com/t5/Unleashed/R320-started-making-requests-to-international-endpoint/m-p/54722#M4902</link>
      <description>&lt;P&gt;Hello. I have two Ruckus R320 APs running 200.12.10.105.129. My router (a Firewalla Gold) notified me last night that the master AP started making requests every few minutes to umm1.exands.com:443, supposedly originating from the AP, and the endpoint being in China.&lt;/P&gt;&lt;P&gt;I did a bit of Googling about the endpoint and couldn't determine anything other than Exands seems to be a "network infrastructure operator". Once I blocked the endpoint, I started seeing umm1.exands.com:53 (DNS) requests instead (also being blocked by my router), similarly originating from the WAP.&lt;/P&gt;&lt;P&gt;This has concerned me, as if it could be malware, but I don't know how to investigate. If it were a plain linux box, maybe I could use something like tcpdump to determine the process making the requests; I can SSH into it, but the Ruckus CLI is limited. Any advice before I wipe and reinstall the APs?&lt;/P&gt;&lt;P&gt;Aside: I notice the master AP is also making constant (seemingly every 2-3min) attempts to captive.apple.com for a long time. I believe that's a tactic used to determine if a device is on a captive network, but is that a feature of Unleashed?&lt;/P&gt;</description>
      <pubDate>Tue, 07 Mar 2023 23:22:23 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/Unleashed/R320-started-making-requests-to-international-endpoint/m-p/54722#M4902</guid>
      <dc:creator>defect</dc:creator>
      <dc:date>2023-03-07T23:22:23Z</dc:date>
    </item>
    <item>
      <title>Re: R320 started making requests to international endpoint</title>
      <link>https://community.ruckuswireless.com/t5/Unleashed/R320-started-making-requests-to-international-endpoint/m-p/54731#M4903</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.ruckuswireless.com/t5/user/viewprofilepage/user-id/18214"&gt;@defect&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;I believe you are not from the exands. Could you please confirm if there is any special configuration done for the AP or with regards to the UMM settings?&lt;BR /&gt;Also, is this the first time the router reported this?&lt;BR /&gt;Any changes done before this issue triggerred?&lt;BR /&gt;Please confirm the AP location (Country)&lt;/P&gt;</description>
      <pubDate>Wed, 08 Mar 2023 03:28:06 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/Unleashed/R320-started-making-requests-to-international-endpoint/m-p/54731#M4903</guid>
      <dc:creator>sanjay_kumar</dc:creator>
      <dc:date>2023-03-08T03:28:06Z</dc:date>
    </item>
    <item>
      <title>Re: R320 started making requests to international endpoint</title>
      <link>https://community.ruckuswireless.com/t5/Unleashed/R320-started-making-requests-to-international-endpoint/m-p/54735#M4904</link>
      <description>&lt;P&gt;&lt;a href="https://community.ruckuswireless.com/t5/user/viewprofilepage/user-id/18214"&gt;@defect&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;BTW, you can disable this feature if you are not using the UMM or any special settings.&amp;nbsp;&lt;SPAN&gt;&lt;SPAN class=""&gt;Go to Unleashed WEB GUI -- Admin&amp;amp;Service --Administration--NetworkManagement--Unleashed MultiSite Manager.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Mar 2023 03:48:27 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/Unleashed/R320-started-making-requests-to-international-endpoint/m-p/54735#M4904</guid>
      <dc:creator>sanjay_kumar</dc:creator>
      <dc:date>2023-03-08T03:48:27Z</dc:date>
    </item>
    <item>
      <title>Re: R320 started making requests to international endpoint</title>
      <link>https://community.ruckuswireless.com/t5/Unleashed/R320-started-making-requests-to-international-endpoint/m-p/54739#M4907</link>
      <description>&lt;P&gt;&lt;a href="https://community.ruckuswireless.com/t5/user/viewprofilepage/user-id/88"&gt;@sanjay_kumar&lt;/a&gt;&amp;nbsp;Thanks for your response. I see now looking at the MSM settings that&amp;nbsp; it was enabled and set to "&lt;A href="https://umm1.exands.com/intune/server" target="_blank" rel="noopener"&gt;https://umm1.exands.com/intune/server&lt;/A&gt;". I have disabled it now.&lt;/P&gt;&lt;P&gt;Is this - "exands.com" - specific to a particular client? Can it be "pushed" to the AP? Or would my AP have had this configured the whole time? I never checked this setting before.&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;nbsp;&lt;SPAN&gt;Could you please confirm if there is any special configuration done for the AP or with regards to the UMM settings?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;No. I bought both of these APs second-hand and installed the Unleashed firmware fresh. This is for home use, just the two APs.&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;nbsp;&lt;SPAN&gt;Also, is this the first time the router reported this?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;This is the first time to my knowledge. I suppose it's possible it happened before, I only have 24 hours of history and it started up suddenly looking at the timeline.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;gt;&amp;nbsp;Any changes done before this issue triggerred?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Not that I can think of. I haven't touched the Unleashed configuration in months.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;nbsp;Please confirm the AP location (Country)&lt;/P&gt;&lt;P&gt;United States.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Mar 2023 04:15:32 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/Unleashed/R320-started-making-requests-to-international-endpoint/m-p/54739#M4907</guid>
      <dc:creator>defect</dc:creator>
      <dc:date>2023-03-08T04:15:32Z</dc:date>
    </item>
    <item>
      <title>Re: R320 started making requests to international endpoint</title>
      <link>https://community.ruckuswireless.com/t5/Unleashed/R320-started-making-requests-to-international-endpoint/m-p/54741#M4908</link>
      <description>&lt;P&gt;&lt;a href="https://community.ruckuswireless.com/t5/user/viewprofilepage/user-id/18214"&gt;@defect&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;"exands" is a specific customer. Probably the AP was holding the configuration. Probably you need to do the Factory default and then load the firmware if you are using a second hand APs.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Mar 2023 04:16:09 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/Unleashed/R320-started-making-requests-to-international-endpoint/m-p/54741#M4908</guid>
      <dc:creator>sanjay_kumar</dc:creator>
      <dc:date>2023-03-08T04:16:09Z</dc:date>
    </item>
    <item>
      <title>Re: R320 started making requests to international endpoint</title>
      <link>https://community.ruckuswireless.com/t5/Unleashed/R320-started-making-requests-to-international-endpoint/m-p/54743#M4909</link>
      <description>&lt;P&gt;I see. I'm pretty sure that I did do a factory reset on both, since I was installing new firmware on both devices, I remember getting the initial setup flow and everything.&lt;/P&gt;&lt;P&gt;So there's no way that the AP had configuration pushed to it? This MSM would have had to be configured the whole time?&lt;/P&gt;</description>
      <pubDate>Wed, 08 Mar 2023 04:19:54 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/Unleashed/R320-started-making-requests-to-international-endpoint/m-p/54743#M4909</guid>
      <dc:creator>defect</dc:creator>
      <dc:date>2023-03-08T04:19:54Z</dc:date>
    </item>
    <item>
      <title>Re: R320 started making requests to international endpoint</title>
      <link>https://community.ruckuswireless.com/t5/Unleashed/R320-started-making-requests-to-international-endpoint/m-p/54744#M4910</link>
      <description>&lt;P&gt;&lt;a href="https://community.ruckuswireless.com/t5/user/viewprofilepage/user-id/88"&gt;@sanjay_kumar&lt;/a&gt;&amp;nbsp;Also, could you comment on the constant calls to captive.apple.com? I can't imagine that's an MSM feature.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Mar 2023 04:21:22 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/Unleashed/R320-started-making-requests-to-international-endpoint/m-p/54744#M4910</guid>
      <dc:creator>defect</dc:creator>
      <dc:date>2023-03-08T04:21:22Z</dc:date>
    </item>
    <item>
      <title>Re: R320 started making requests to international endpoint</title>
      <link>https://community.ruckuswireless.com/t5/Unleashed/R320-started-making-requests-to-international-endpoint/m-p/54746#M4911</link>
      <description>&lt;P&gt;This is from the apple devices like iphones and MAC when connecting to SSID to determine if the captive portal is enabled or not.&lt;BR /&gt;This is by design.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Mar 2023 04:24:53 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/Unleashed/R320-started-making-requests-to-international-endpoint/m-p/54746#M4911</guid>
      <dc:creator>sanjay_kumar</dc:creator>
      <dc:date>2023-03-08T04:24:53Z</dc:date>
    </item>
    <item>
      <title>Re: R320 started making requests to international endpoint</title>
      <link>https://community.ruckuswireless.com/t5/Unleashed/R320-started-making-requests-to-international-endpoint/m-p/54747#M4912</link>
      <description>&lt;P&gt;I understand what it's normally for, but why is the traffic originating from the AP? I also occasionally see calls to time.google.com, but Unleashed is set to use ntp.ruckuswireless.com.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Mar 2023 04:29:29 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/Unleashed/R320-started-making-requests-to-international-endpoint/m-p/54747#M4912</guid>
      <dc:creator>defect</dc:creator>
      <dc:date>2023-03-08T04:29:29Z</dc:date>
    </item>
    <item>
      <title>Re: R320 started making requests to international endpoint</title>
      <link>https://community.ruckuswireless.com/t5/Unleashed/R320-started-making-requests-to-international-endpoint/m-p/54748#M4913</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.ruckuswireless.com/t5/user/viewprofilepage/user-id/18214"&gt;@defect&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For the NTP, both the URL are actually same resolving to same IP address 216.239.35.0.&lt;BR /&gt;&lt;BR /&gt;For the captive.apple.com,&amp;nbsp;&lt;SPAN&gt;The URL&amp;nbsp;captive.apple.com &amp;lt;&lt;A href="https://captive.apple.com/" target="_blank"&gt;https://captive.apple.com/&lt;/A&gt;&amp;gt;&amp;nbsp;is apple CNA (Captive Network Assistance) URL. It is different for Android and windows client devices.&lt;BR /&gt;When apple device connect to any captive portal enabled SSID, it auto pop-up the browser and try to access&amp;nbsp;captive.apple.com &amp;lt;&lt;A href="https://captive.apple.com/" target="_blank"&gt;https://captive.apple.com/&lt;/A&gt;&amp;gt;&amp;nbsp;to redirect to the portal's splash page. After successful authentication the client will be redirected to&amp;nbsp;redirect&amp;nbsp;captive.apple.com &amp;lt;&lt;A href="https://captive.apple.com/" target="_blank"&gt;https://captive.apple.com/&lt;/A&gt;&amp;gt;&amp;nbsp;as the default start page configuration is "URL that the user intends to visit".&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;If you need to understand where is the actual request is coming from, then you can take the packet from the AP.&lt;BR /&gt;From GUI:&lt;BR /&gt;1. Go to Admin &amp;amp; Services &amp;gt; Administration &amp;gt; Diagnostics &amp;gt; Packet Capture.&lt;BR /&gt;2. For Radio, select 2.4 GHz or 5 GHz.&lt;BR /&gt;3. Under Currently Managed APs, select APs from the list and click Add to Capture APs.&lt;BR /&gt;4. Select Local Mode or Streaming Mode as the capture mode.&lt;BR /&gt;• To capture a limited snapshot on each AP, select Local Mode.&lt;BR /&gt;a. Click Start to begin capturing packets.&lt;BR /&gt;b. Click Stop to end the capture.&lt;BR /&gt;c. Click Save to save the packet capture to a local file.&lt;BR /&gt;• To stream the captured packets to Wireshark, select Streaming Mode.&lt;BR /&gt;a. Click Start to launch Wireshark.&lt;BR /&gt;b. Select Capture Options. Under Capture: Interface, select Remote. A Remote Interface dialog box is displayed.&lt;BR /&gt;c. Under Host, enter the IP address of the AP you want to view. Leave the Port field empty and click OK.&lt;BR /&gt;The remote host interface list on the right side is updated.&lt;BR /&gt;d. Select wifi0 or wifi1 from the list, depending on whether you are streaming on the 2.4-GHz or 5-GHz radio.&lt;BR /&gt;5. Click on Start.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Mar 2023 04:39:41 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/Unleashed/R320-started-making-requests-to-international-endpoint/m-p/54748#M4913</guid>
      <dc:creator>sanjay_kumar</dc:creator>
      <dc:date>2023-03-08T04:39:41Z</dc:date>
    </item>
    <item>
      <title>Re: R320 started making requests to international endpoint</title>
      <link>https://community.ruckuswireless.com/t5/Unleashed/R320-started-making-requests-to-international-endpoint/m-p/54754#M4914</link>
      <description>&lt;P&gt;I appreciate the detail, but I'm still confused; I do understand that captive.apple.com is how a device can check to see if it's behind a captive portal. I'm not running a captive portal, and more importantly: my&amp;nbsp;router doesn't report _all_ traffic that happens to be traversing the access point (like web requests from my devices on wifi). It's reporting that connections to "captive.apple.com" are _originating_ from the AP. In other words, it's not that some android or ios device is checking that URL, at least if I'm interpreting this correctly.&lt;/P&gt;&lt;P&gt;What am I looking for in the dump in Wireshark to discern the source? I've looked at TCP and HTTP traffic before, but I haven't been able to find anything that would help me identify this CNA traffic.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Mar 2023 06:10:34 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/Unleashed/R320-started-making-requests-to-international-endpoint/m-p/54754#M4914</guid>
      <dc:creator>defect</dc:creator>
      <dc:date>2023-03-08T06:10:34Z</dc:date>
    </item>
    <item>
      <title>Re: R320 started making requests to international endpoint</title>
      <link>https://community.ruckuswireless.com/t5/Unleashed/R320-started-making-requests-to-international-endpoint/m-p/54755#M4915</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.ruckuswireless.com/t5/user/viewprofilepage/user-id/18214"&gt;@defect&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;Even if the AP is not bradcasting a Captive portal enabled SSID, the apple client by default it will send a query to preconfigured URL captive.apple.com whenever it connects to the SSID.&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Since the Firewall is pointing that the source is AP, we can take the capture on the AP to see the real source.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;You can follow the steps mentioned to take the capture, or you can open a support case so that the TAC team can help you on this.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Mar 2023 06:10:23 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/Unleashed/R320-started-making-requests-to-international-endpoint/m-p/54755#M4915</guid>
      <dc:creator>sanjay_kumar</dc:creator>
      <dc:date>2023-03-08T06:10:23Z</dc:date>
    </item>
    <item>
      <title>Re: R320 started making requests to international endpoint</title>
      <link>https://community.ruckuswireless.com/t5/Unleashed/R320-started-making-requests-to-international-endpoint/m-p/54756#M4916</link>
      <description>&lt;P&gt;I understand that the CNA URL will be accessed. And it would make sense if my router was reporting that my mobile devices were accessing it, but the source of the connections are the master AP's MAC address. That's what is confusing me.&lt;/P&gt;&lt;P&gt;I did perform a capture per your instructions but I'm having trouble interpreting. I'll see if I can get help via support ticket, thanks for your time.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Mar 2023 06:14:44 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/Unleashed/R320-started-making-requests-to-international-endpoint/m-p/54756#M4916</guid>
      <dc:creator>defect</dc:creator>
      <dc:date>2023-03-08T06:14:44Z</dc:date>
    </item>
    <item>
      <title>Re: R320 started making requests to international endpoint</title>
      <link>https://community.ruckuswireless.com/t5/Unleashed/R320-started-making-requests-to-international-endpoint/m-p/54757#M4917</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.ruckuswireless.com/t5/user/viewprofilepage/user-id/18214"&gt;@defect&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;Sure, let me the case number once you create it.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Mar 2023 06:16:18 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/Unleashed/R320-started-making-requests-to-international-endpoint/m-p/54757#M4917</guid>
      <dc:creator>sanjay_kumar</dc:creator>
      <dc:date>2023-03-08T06:16:18Z</dc:date>
    </item>
    <item>
      <title>Re: R320 started making requests to international endpoint</title>
      <link>https://community.ruckuswireless.com/t5/Unleashed/R320-started-making-requests-to-international-endpoint/m-p/54758#M4918</link>
      <description>&lt;P&gt;Case number is 01444881&lt;/P&gt;</description>
      <pubDate>Wed, 08 Mar 2023 06:26:26 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/Unleashed/R320-started-making-requests-to-international-endpoint/m-p/54758#M4918</guid>
      <dc:creator>defect</dc:creator>
      <dc:date>2023-03-08T06:26:26Z</dc:date>
    </item>
    <item>
      <title>Re: R320 started making requests to international endpoint</title>
      <link>https://community.ruckuswireless.com/t5/Unleashed/R320-started-making-requests-to-international-endpoint/m-p/54759#M4919</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.ruckuswireless.com/t5/user/viewprofilepage/user-id/18214"&gt;@defect&lt;/a&gt;&lt;BR /&gt;Check out this thread, I hope it might help you.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://community.ruckuswireless.com/t5/Access-Points-Indoor-and-Outdoor/DNS-Requests-to-baidu-com-from-Unleashed-AP/m-p/39502/page/2" target="_blank"&gt;https://community.ruckuswireless.com/t5/Access-Points-Indoor-and-Outdoor/DNS-Requests-to-baidu-com-from-Unleashed-AP/m-p/39502/page/2&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Mar 2023 06:32:49 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/Unleashed/R320-started-making-requests-to-international-endpoint/m-p/54759#M4919</guid>
      <dc:creator>sanjay_kumar</dc:creator>
      <dc:date>2023-03-08T06:32:49Z</dc:date>
    </item>
  </channel>
</rss>

