Welcome to the Cox Community
Our community is a collaborative place to learn about Cox products and services. Jump into the conversation today!
Messages
Selected Messages
Our community is a collaborative place to learn about Cox products and services. Jump into the conversation today!
New Contributor
•
18 Messages
Closed
Okay, so I went from using 77-100 GB on average EVERY month, NEVER once having come close to going over my data usage. My MAX data usage allotted is 250GB. Two weeks ago, I get an email from COX saying I've gone over that limit. Again, this has NEVER happened before and generally I don't even use HALF of the data I'm allowed. Now I'm pushing almost twice that allotment. I'm at 424GB for the month. Again, last month was 77GB.
Okay, so, I started looking around on my CISCO router, which is setup for WPA2 security. Note this is COX's equipment I'm renting. It's a CISCO 3825.
After I logged in, I went to Status > ARP/RARP Table and I see the following:
I don't know if this is related or not but I'm wondering if this is an entry that belongs here. I did a lookup on the MAC address listed and it's of a Cisco origin. Note that it is NOT my Cisco router. I have verified that the MAC addresses are completely different.
I have tried adding this MAC address to both the LAN and WAN Mac Filtering black list on my router. However, it still shows up if I hit refresh. Can anyone help me verify if these are valid entries? The IP addresses are not my own. In fact, they are far outside the range of my own 192.168.X.X variety. If not, could someone be using ARP spoofing to direct traffic to their own router? I'm not entirely sure how that works. I have tried calling COX today and talked to Home Networking but they did not address my concern specifically - only advising me to what I've already done. I'm POSITIVE this data is not coming from a sudden onset of increased usage on my part. I believe someone might be using my connection for their own.
What can I do? Please help!
Discussions
•
Updated
11.6K
32
0
0
Unlimited Data?
Discussions
1
0
Bill to high
Discussions
1
0
Data usage by device
Discussions
3
0
After 1 year, what will our plan pricing be?
Discussions
2
0
Variety pack
Discussions
1
0
They don’t care
Discussions
1
0
Worst Service Ever!
Discussions
1
0
SSID & Password
Discussions
1
0
Disney plus won’t play shows
Discussions
1
0
theswift
New Contributor
•
Sorry that I can't help, I'm going through this as well. I made this thread earlier today - http://forums.cox.com/forum_home/internet_forum/f/5/t/5030.aspx
0
0
Bingly
New Contributor
•
Thanks! Hopefully we can figure this out. Your situation sounds similar to mine.
0
0
Health_Edge
+5 more
Valued Contributor III
•
Interesting. Those are private IP's. ARP requests are created by a network device when it's trying to find the owner (MAC address) for a certain IP. I looked at the manual, page 87 says:
"Click ARP/RARP Table to see a complete list of all devices that are connected to your network."
So that would seem to insinuate the ARP requests are coming either from the gateway itself or your LAN. Try refreshing it, then try to ping one of the IPs. If you get a response, type arp -a and that should give you the MAC address of the device with that IP. If its not a IP within any of your DHCP ranges, and you can ping it, then you must have some rogue device (printer, phone,xbox,etc,?) on your network.
If you can't ping it, then I think something else is going on. They might either be the IP address for the WAN interface on the gateway (NOT the WAN interface of your router) or the private IP assigned to the HFC MAC address of the gateway. To check for that, try a tracert to anything on the internet and see if you get anything like the 10.165.x.x-10.177.x.x range on the 2nd to 3rd hop.
As a general question, I am curious why you are using a gateway with another router? If you have a Cisco router already configured, then it may be easier to just avoid the problem all together by getting a stand alone modem. If nothing else it would simplify the situation.
0
0
Health_Edge
+5 more
Valued Contributor III
•
Do you also have a DPC3825?
0
0
Bingly
New Contributor
•
Okay, I pinged the first private IP. So it definitely has a response. Going to try arp -a next, I guess.
0
0
Health_Edge
+5 more
Valued Contributor III
•
Try a tracert to the IP too. That will tell you if its off your gateway's LAN or your router's LAN.
0
0
Bingly
New Contributor
•
It traceroutes to the CISCO 3825 >> 192.168.0.1
0
0
Bingly
New Contributor
•
I should also mention that I have had DHCP disabled for a long time now and ALL of my devices are given static IPs. The private IPs you see in the image above are NOT any of my recognizable devices.
0
0
Health_Edge
+5 more
Valued Contributor III
•
How is your network configured? In your original post I thought you said you had a Cisco router? But if so, that would show up in any tracert. Were you talking about the gateway?
If not, then it sounds like something is connecting to your gateway, and most likely wirelessly. Try disabling the wireless on the gateway and see if you can still ping it. A device doesn't need DHCP to use a IP if it has it's IP assigned static.
0
0
Bingly
New Contributor
•
The CISCO is a modem/router combo that I rent from COX. That is my gateway.
What troubles me is that I can ping these IPs.
I should also note that today I added ONLY my computer to the whitelist on the Wifi Mac Address list. If they're connecting via WiFi, they're somehow getting around the whitelist I've assigned which only has one device on it.
0
0
Bingly
New Contributor
•
I also want to mention that today I have done the following, which would also further secure the WiFi:
• Changed SSID
• Changed WPA2 key
• Disabled WiFi broadcast
0
0
Health_Edge
+5 more
Valued Contributor III
•
So to be clear, your network only consists of the DPC3825, one computer hardwired to the DPC3825 and a number of wireless computers?
Also, if your running Windows 7, try going to Start > Computer > "Network" on left side of window. That should map devices on your network and maybe give you a device name to go with the MAC.
0
0
Bingly
New Contributor
•
Not hard-wired. The CISCO has its own Mac Filtering options for WiFi. My computer is the only device on that WiFi whitelist so I'm the only one able to connect to it wirelessly.
I'm not on Windows, I'm running OSX.
0
0
Health_Edge
+5 more
Valued Contributor III
•
OSX doesn't have any built in network discovery tools, but a common open source program you can try is http://angryip.org/
You don't have anything else connected to the ethernet ports on the back of the Cisco/DPC3825? If not, then it sounds like the 10.x.x.x IPs are inside the gateway itself. That would explain why the MAC address has a Cisco vendor assigned to it. Try going to Administration > Diagnostics in the Cisco and ping the IP from there.
0
0
Bingly
New Contributor
•
Nothing else is connected to the back of the CISCO. The only thing connected now is my computer. The IPs are still there.
One thing that is kind of strange is that the IPs fluctuate. Some of them disappear and then don't reappear until I refresh several more times.
0
0