Most visitors decide in 5 seconds whether they understand what you do. Ours is a free, no-pressure look at your site.

Rogue DeviceNetwork LoopEnd User Error

How a $15 Switch Took Down a 300-Person Office

Patryk Stanczak, Founder & CEOJanuary 15, 20265 min read
GH

Geek Heros War Stories

Monday Morning Chaos

It started like a bad joke: 300 people walk into an office, and nobody can connect to anything. Workstations couldn't reach the file server. Email was intermittent. VoIP phones were dropping calls mid-conversation. The internet worked sporadically — pages would load, then timeout, then load again.

The symptoms were maddening because they weren't consistent. Some users were fine for stretches, then suddenly couldn't connect. Others were affected from the moment they logged in. There was no clear pattern by location, department, or device type.

The Investigation

We started with the core infrastructure. The main switches were operational. The firewall was up. The ISP connection tested clean. Server resources were normal. Everything at the center of the network looked correct — which meant the problem was somewhere at the edge.

We began systematically checking switch port statistics, looking for anomalies. And we found one: a single port on a floor switch was generating an extraordinary volume of broadcast traffic. The traffic pattern suggested a routing loop — packets being sent in circles, consuming bandwidth and confusing the switching infrastructure.

We traced the port to a specific office. And there, plugged into the wall jack behind a desk, was a $15 consumer-grade 5-port Ethernet switch.

What Happened

A manager had brought the small switch from home. She needed to connect a second monitor's USB dock and a personal laptop to the network, and her office only had one wall port. Rather than requesting IT to add a port, she plugged in her own switch over the weekend.

The problem was how it was connected. The switch created a configuration that caused the network's spanning tree protocol to recalculate — and in this case, the tiny consumer switch briefly became the root bridge for the network segment. Routing tables updated. Packets that should have gone to the core switch were being routed through a $15 device designed for a home office.

The result was widespread network instability affecting all 300 users.

When asked about it, the manager didn't mention the switch. She didn't think it was relevant. "I just plugged in a little thing for my laptop" — in her mind, it was no different from plugging in a desk lamp. She had no idea that a network switch could affect anything beyond her immediate desk.

The Fix

Unplugging the consumer switch resolved every issue instantly. Three hundred users went from intermittent connectivity to full normal operation in the time it took to pull a cable.

We then configured the managed switches throughout the building with proper spanning tree protocol guards — BPDU Guard and Root Guard — to prevent any unauthorized switch from being able to influence the network topology in the future. We also enabled port security on user-facing switch ports to detect and alert on unauthorized devices.

What This Means for Your Firm

This story sounds almost too simple to be real, but it's one of the most common causes of network disruption we encounter. Unauthorized devices on corporate networks cause problems ranging from minor performance degradation to complete network outages.

Key takeaways:

- No unauthorized network devices. This should be a written policy. If someone needs additional network ports, IT provisions them properly. - Managed switches with security features. Consumer-grade switches have no place in a business network. Managed switches with BPDU Guard, Root Guard, and port security prevent rogue devices from affecting the network. - End user education. Staff need to understand that network devices are not like desk accessories. Plugging in a switch, a wireless access point, or even a USB hub with Ethernet can have network-wide consequences. - Port monitoring. IT should have visibility into every device connected to every switch port. Unauthorized devices should trigger alerts.

The scariest part of this story isn't that it happened — it's how long it took to find because the user didn't think to mention it. A quick "I plugged something in over the weekend" would have saved an entire morning of troubleshooting.

Worried about unauthorized devices on your network? [Get a free site audit](#assessment) — we'll audit your network security and identify risks before they take down your office.

Get Your Free Site Audit

Find out where your firm stands on security, compliance, and IT performance — at no cost.

Related Articles

Ready to see where your brand stands?