This device “android-e5ab33ce2699c483” with a MAC address 38:aa:3c:71:3e:8b hooking up to IPSOS-GUEST network has been blocked at the UTM firewall. I suspect that this is what has been causing 100% CPU load on the firewall during the past week.
The way it has been blocked is by fixing its IP address on the DHCP server, the UTM firewall in this case, to an IP range of 172.22.23.201 onwards. Traffic from any devices in this range of IP addresses to outside is configured to be dropped. In the future we should be able to do the blocking at a Windows DHCP server for this VLAN, by assigning no default route to the blocked devices, but since the DHCP server for IPSOS-GUEST is currently the UTM so for now we have to do it at the UTM.
Let’s keep an eye on the UTM’s CPU load from now. If it turns out this device was not the culprit then we will unblock it. Meanwhile, if the user asks we can tell them to go fix the problem on their device first before it can be allowed back on the IPSOS-GUEST network. It probably needs a re-installation of Android. Note that we do not officially support users’ personal devices especially not during office hours. If, however, the user would like any of you to play with it outside working hours then it’s up to you