Jump to content

Recommended Posts

Posted

Would it be possible to use a cheap SDR like the RTL-SDR's to scan for LTE?

 

I have a couple of these guys I've used for scanning narrow band transmissions on many frequencies:

http://www.amazon.com/RTL-SDR-RTL2832U-Popular-Software-Packages/dp/B00C37AZXK

 

The limitations that come to mind is I think the widest channel bandwidth is only 2.8MHz, and the max frequency you can tune to is 1700MHz.

 

I'm wondering if it would be useful for discovering LTE Band 26 deployments.

 

Posted

No.  Assuming whatever SDR supported the correct frequencies, you would need to still analyze the signal in order to determine what it is.  Maybe you could make a guess by checking out subcarrier spacing, but it wouldn't be exact and it wouldn't determine the carrier (provider).  Far too many opportunities for false positives if you ask me...

  • 4 months later...
Posted

Would it be possible to use a cheap SDR like the RTL-SDR's to scan for LTE?

 

I have a couple of these guys I've used for scanning narrow band transmissions on many frequencies:

http://www.amazon.com/RTL-SDR-RTL2832U-Popular-Software-Packages/dp/B00C37AZXK

 

The limitations that come to mind is I think the widest channel bandwidth is only 2.8MHz, and the max frequency you can tune to is 1700MHz.

 

I'm wondering if it would be useful for discovering LTE Band 26 deployments.

 

Or just go this route like a few of us did...

 

http://s4gru.com/index.php?/topic/4455-shopping-for-an-spectrum-analyzer-rf-explorer/

 

I use it from time to time to check to see if the 1x800 rollout or 800LTE has started here.  Also great for finding 1900 LTE sites in test mode.  You can hook it up to a computer as well for a better look at things

 

NL03ME017_BTR_2.jpg

Posted

Or just go this route like a few of us did...

 

http://s4gru.com/index.php?/topic/4455-shopping-for-an-spectrum-analyzer-rf-explorer/

 

I use it from time to time to check to see if the 1x800 rollout or 800LTE has started here.  Also great for finding 1900 LTE sites in test mode.  You can hook it up to a computer as well for a better look at things

 

 

 

That seems like a good option. The cheapo RTL-SDR's are not very useful for decoding broadband signals. I've actually been considering a high end SDR like the USRP B200: https://www.ettus.com/product/details/UB200-KIT

 

It's quite expensive but it has all the features I want. Broadband RF support, 70MHz to 6GHz, sampling up to 56MHz wide channels, and you can actually transmit with it. I went to a conference where they gave a presentation on the interesting things you can do with these:

  • 1 month later...
Posted

I wrote instructions on how to start with nothing and end up with a fully function SDR based LTE scanner at my blog here: http://www.shawngarringer.org/2014/01/14/set-up-your-own-kali-linux-usb-dongle-with-support-for-lte-cel-scanner/

 

Total cost about $50, $30 for the RTL-SDR and about $20 for the USB thumb drive for persistence.  Steps you through configuring the USB drive, installing Kali, building the LTE-Scanner toolchain, and scanning frequencies. I use this all the time to map new LTE sites coming online for carriers in my area.

  • Like 1
Posted

Ever wonder what LTE looks like in a waterfall?

 

 

I actually just recorded that with my new USRP. This thing is sweet!

 

What you see in that video is my phone getting taken out of airplane mode, authenticating with the network, and logging into tapatalk.

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • large.unreadcontent.png.6ef00db54e758d06

  • gallery_1_23_9202.png

  • Posts

    • It took a couple of months but this site is finally back online.  I was certain that a decommission permit would come through one day since it was offline for over 3 months but I passed by it today and it was working again. — — — — — This site is also finally live. This was probably the longest I had ever seen a site take to go live once all hardware was installed, about 3 months. Hopefully the site in Long Island City doesn't take as long.
    • So while we wait for @RAvirani to fix the website, I was able to connect one of my phones to Verizon n77 on a site with an NCI that appears to be adjacent to an NCI that was already in my database. Specifically, the site I call Taylor Run has been observed with these NCIs on n77: 44EEE469A 44EEE46AA 44EEE46AB 44EEE46BA 44EEE46BB I separately connected to the site I call Fairlington on its beta sector on n77: 44EEE46DA 44EEE46DB I'm assuming alpha sector is 44EE46CA/B.  With this data, I learned two things: 1) They're clearly not tracking the LTE GCIs with the NR NCIs.  Taylor Run is 1B61Fxx, while Fairlington is 1B680xx, not sequential. 2) It's clear that they're not using three byte sectors.  They're not even using two byte sectors like LTE does.  It looks to be done in an oddball fashion like how Dish is doing things.  Best I can come up with is a site ID that's something like: (NCI-0x20)/(0x30) It's possible it's actually (NCI+0x10)/(0x30) but I'm not really sure.  I also haven't connected to anything outside my immediate area here to know if this is consistent with other regions.  Not entirely sure how to persuade a device to do so, my Dish phone just connects to n77 at random in lieu of going to no signal.  (No data passes.) My take is to "break" the site notes for Verizon NR the way it was done with Dish NR, so at least the notes don't get copied to inconsistent sites, as has happened when I connected to Fairlington (came up as "Taylor Run").  It seems that Verizon, AT&T, and Dish all need work on the NR side to make sure site notes work properly.  Frustrating that they didn't standardize that for NR the way they did for LTE.  T-Mobile and US Cellular (while it lasts) seem to have done it the way I would have done it.  The others, not so much. - Trip
    • I tried to access that forum but it says I need a password. Is it limit to certain contributors?    I was going to report that the website is broken. For days it's been saying unable to retrieve signal data then going to a 404 error.
    • Sorry, I forgot about it when I posted previously.  And then I was talking to chamb by e-mail and away from my computer and suggested posting here.  Moved the posts to the proper spot. - Trip
    • It is probably better to post topics related to the map in the dedicated thread to help keep things organized and secure. This thread is big enough as it is, just want to try help keep things on track!
  • Recently Browsing

    • No registered users viewing this page.
×
×
  • Create New...