Device changes group (because IP changes?)

Comments

9 comments

  • Avatar
    Firewalla

    Sorry about the problems;  is the problems mainly with macbooks?  Do you have any other devices in the home that does network extender or another router behind firewalla gold?  if not, we need need to look inside.  Can you please send an email to help@firewalla.com, we may need support access.  Please reference to this thread when you send the email, so you don't have type everything again. 

    0
    Comment actions Permalink
  • Avatar
    Wallace Mann

    I have attached an image showing our network layout.  The only other "router" is the TP-LINK, but it has been set up as an access point.  

    All of our personal computers are MacBooks.  If the problem is occuring with other devices I would not know because we only put device controls on the MacBooks.  The MacBooks are different ages (ranging from brand new to 2014) and different OS (ranging from Majove to Catalina).  

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    Thank you for the diagram.  Will follow up with you in the case and see if we can resolve it. 

     

    0
    Comment actions Permalink
  • Avatar
    Wallace Mann

    I've enabled support and sent id/pw by email.

    In case it's helpful, I've noticed the problem most with Niko Book and GordianKnotcutter machines.  This morning GordianKnotcutter (the Daddy machine) ended up in the Niko group.  

    0
    Comment actions Permalink
  • Avatar
    Wallace Mann

    We took our Firewalla to a rental home for 2 days because of a power outage at home.  Then we came home and brought it back.  Everything worked, but ... oh, my, it's like all the device groups got scrambled.  Devices got dropped from groups.  Devices got moved into a different group.  Rules stayed with the group, but it meant that for a few hours most of our machines were either abnormally blocked or abnormally permissive.

    I'm surprised more people aren't experiencing this. It's both annoying and common for us.  And I'm shocked that this can't be easily prevented since you have access to the mac address.  I can understand how by disassembling and moving my network all the IP addresses get scrambled, but why this confuses Firewalla so much is surprising.

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    @Wallace, can you please check on your devices if they have changed MAC?   Firewalla grouping all done via MAC addresses.

    0
    Comment actions Permalink
  • Avatar
    Wallace Mann

    Finally!  That's the problem. 

    My networking knowledge was obsolete.  I had never heard of MAC address randomization.  What a nightmare.  I will see if I can disable that lovely feature..

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    @Wallace

    Yes, it is a nightmare for security people.  Hiding devices by randomizing MAC in a trusted network does not benefit security.  It is like wearing a disguise in public to stop camera's tracking you, now doing that at home ... 

    0
    Comment actions Permalink
  • Avatar
    Wallace Mann

    I found our other problem!  It was the DONGLES! 

    We did have phones using MAC address randomization (not any more), but we had yet another problem.  All of our computers are MacBooks which actually do not use randomization.  But all of our computers use hardwired Cat5 ethernet via j5create usb-c docking stations and ... the MAC address lives in the dongle.  Not realizing this was an issue, during the course of a week and moving machines around, we occasionally swapped dongles.  When we moved to and from the rental house, moving the whole setup resulted in mass dongle swapping and thus mass group re-assignment.

    There's probably a feature request in here somewhere, maybe the ability to alert when a computer of a given name changes group, but for now we can defend against the issue with careful dongle management.

    0
    Comment actions Permalink

Please sign in to leave a comment.