How to turn off MAC Address Randomization?

Follow

Comments

11 comments

  • Avatar
    Zeeshan Yousuf

    How parental controls can be effective if kids on their iphone keep using private Mac address? Just bought FWG and trying to find a solution to this issue. Is there an option in FWG to implicitly deny any new Mac address?

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    @Zeeshan, the best way is always talking to the kids first. If that fails, you should turn on this feature, https://help.firewalla.com/hc/en-us/articles/360058853313-Firewalla-New-Device-Quarantine

    Device quarantine will block all new devices from accessing internet until you approve

    2
    Comment actions Permalink
  • Avatar
    mobius strip

    @Zeeshan in addition to the suggested solution by @Firewalla, I believe 2 other methods can further help with this as well as  give you additional traffic control options:

    A.) Strongest solution for this and securing your networks in general that I’m aware of that’s also relatively practical to implement is: 

    Get a Wi-Fi AP that has both a built-in radius server and VLAN support, and use WPA2-AES (Enterprise) or newer Enterprise Wi-Fi security which is generally the strongest practical way of identifying each unique user on any Wi-Fi network.

    Use this Enterprise security on SSID’s that have user-configurable devices (I.e. non-IOT devices, and put those on a separate VLAN & SSID. Use mdns forwarding between subnets if required).

    I suggest an HP/Aruba IAP access point used from eBay. These are locally controllable/configurable, have a built in RADIUS server, and they do not require license fees in order to download the latest firmware, and while they are no longer being made they are still supported for a few more years.

    OR 

    B.) if you don’t want to use wifi enterprise security, just Get a VLAN aware wireless Access Point and give the kids their own SSID associated with a unique VLAN #. This way firewall rules can just be applied to the entire VLAN of that SSID.

    Requires not telling the kids the password to the other SSID used by the parents on a different VLAN, and making sure the kids cannot get the password from your other devices (e.g. a Wi-Fi password on one unlocked iPhone can be shared with another iPhone/iPad by to holding them next to each other)

    In either case I would still auto quarantine as @Firewalla suggests.

     

     

    1
    Comment actions Permalink
  • Avatar
    Russ Michaels

    Zeeshan Yousuf

    I have found the quarantine to be very flaky and unreliable.

    Quarantined devices are usually not actually blocked from anything.

    In fact Firewalla in general is not very reliable, and rules/blocks are often just not working in general.

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    @Russ, can you give an example of quarantine not blocking? (and also double check if you have rules applied to the quarantine to make sure they are blocking or configured to do what you want to do?)

    As of general rules not working, need an example too.

    0
    Comment actions Permalink
  • Avatar
    Russ Michaels

    I would have thought this is self explanatory.

     

    EXAMPLE: a new device connects to the network.... and nothing is blocked, it has full access to the internet.
    If you select the device in firewalla, it says it is quarantined, and internet access is blocked.

    This doesn;t just apply to quarantine either, it applies to blocks in general. Enabling blocks, even the entire internet access block, often has no effect.

     

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    Can you please check the rules or the rules applied to the quarantine group? do you see block internet rule on it? if it does and your device can still talk to the internet, please contact support, likely something else is going on

    0
    Comment actions Permalink
  • Avatar
    Russ Michaels

    the quarantine group has all internet access blocked by default. 

    But I think you are completely missing the point here. As stated above , blocks in general often have no effect, not just for quarantine.

    as in go to any device, and click one of the block buttons, and it might have no effect whatsoever.

    I have already contacted support, I spend many months going back and ofrth repeating the same steps again and again and again.... and got nowhere.

    The firewalla is just unreliable and useless for parental control, so I gave up. 

    I tried to claim a refund, but due to many months support dragged the ticket on for, this put me outside the warranty period, so I was told tough luck,

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    Russ, I am looking at your cases; the issue is very likely that your router is incompatible with Firewalla Red's simple mode. Our staff has suggested using the DHCP mode instead, and most of the time, this will fix the issue. 

    This article here explains the modes https://help.firewalla.com/hc/en-us/articles/115004292514-How-does-Firewalla-Intercept-Traffic-Which-Firewalla-mode-to-use-

    And this explains DHCP mode https://help.firewalla.com/hc/en-us/articles/115004304114-Everything-about-Firewalla-DHCP-Mode-

     

     

    0
    Comment actions Permalink
  • Avatar
    Russ Michaels

    I cannot use DHCP mode, it doesn't work properly and causes even more issues.

    I have mentioned this dozens of times in my tickets.

    0
    Comment actions Permalink
  • Avatar
    Unknown X

    I realize this is an old thread, but as a longtime Firewalla user, I thought I’d chime in. I’ve had similar issues in the past, but as the software improved and I upgraded my router, things stabilized quite impressively, in fact. I’ve always used Router Mode as per Firewalla's guidance, and it’s been excellent.

    Russ, I get where you’re coming from, but in setups like ours, compatibility is everything. I haven’t used DHCP Mode personally, but it can address the kind of inconsistencies you mentioned, especially in complex networks. Switching modes might’ve highlighted what was causing the issue with your router, and sometimes, trying a few adjustments—like going from Simple to Router or DHCP Mode—makes all the difference.

    To the Firewalla team: you handled this situation well. Your patience in suggesting diagnostics, like trying different modes, speaks to your dedication. Network troubleshooting can take time, but the clarity you provided on mode differences was spot on. It's easy to get frustrated when things don’t work instantly, but I’ve seen firsthand how a few small tweaks can smooth everything out.

    Russ, if you're still around, I’d encourage you to stay open to trying those suggestions. Firewalla’s continuous updates and feature improvements have transformed the experience for many of us, and I’m confident that with the right setup, your issues could have been resolved.

    0
    Comment actions Permalink

Please sign in to leave a comment.