FWP Quarantine Question/Pointers?
I have my FWP set to quarantine all my networks. While this is driving me nuts, releasing user devices, I keep thinking, would you rather have a network free of hackers or know what every single device is and to what network it should belong? With that out of the way, my daughter recently got a new iPad, and it was placed in the new device quarantine. So far so good, I turned off "Mac Address Randomization" released the device and everyone was happy. Today, I decided to do some testing of the new device quarantine. I have a main Wi-Fi and a kids' Wi-Fi SSID. If I put myself on either SSID, I must release my machine every time unless I give myself a static IP. Also, while configuring, some new devices popped into the quarantine that I didn't recognize, and they said unknown.lan, and they had "Mac Randomization" on. I still can't find these devices, and I have looked at every MAClookup tool website I can think of, but I don't know what to do. I know I can keep deleting anything that says unknown.lan, but I like to keep the quarantine clean and to know what every device is.
I am using a Ubiquiti Cloud Gateway Ultra as my router, and I don't see those devices listed in the "Clients" list on the Ubiquiti Cloud Gateway Ultra.
I guess I am wondering: Are there better ways of doing what I am doing? Or do I keep chasing down devices and just live with that?
-
MAC Randomization's goal is to hide your devices... while this mechanism is good if you are using public WiFi, it creates huge issues when you want to control them. So the best way is to turn off Mac randomization or ... block the internet if you see Mac randomization is on. (via the network quarantine rules)
I am not sure how you are going to keep quarantine clean when MAC RANDOMIZATION is on ...
Please sign in to leave a comment.
Comments
1 comment