Existing devices being Quarantined as if New

Comments

18 comments

  • Avatar
    FirewallaSupportDesk

    When each time the devices are identified as quarantined, were their MAC addresses the same as before they were added to quarantine? Double Check to make sure device quarantine is off. Firewalla uses MAC addresses to identify new devices. Keeping to be added back to quarantine shall not be related to Active Protect. 

    Are you using Firewalla AP7 for WiFi, and do you have micro-segment applied on the WiFi SSID? 

    0
    Comment actions Permalink
  • Avatar
    Geeklord

    Hi, and thanks.

    It happened again this morning to my wife's phone.

    I don't have the AP7. I'm using wired TP-Link Omada AP's with a hardware controller.

    New device quarantine is turned on. But isn't that preferred for security?

    MAC address is different.

    New device alert and device detail shows her usual phone IP for the New device. Her actual device shows no IP assigned.

    This seems to later resolve it with the quarantine device changing to unknown IP having released it back to her device.

    0
    Comment actions Permalink
  • Avatar
    Firewalla CM

    Hi Geeklord, if the MAC address is different, Firewalla will treat this as a new device. Can you share the type of device this keeps happening to? 

    Please double-check if MAC randomization is truly disabled. If it's an Apple device, we recommend turning Private Wi-Fi Address "Off" completely, instead of using "Fixed" mode. See here: https://help.firewalla.com/hc/en-us/articles/360055342613-How-to-turn-off-MAC-Address-Randomization

    0
    Comment actions Permalink
  • Avatar
    Geeklord

    Hi there. Happens to both mine and my wife's phone, but also others, but it's less noticeable because they're not necessarily in use at the time and it eventually resolves itself.

    Both are Google Pixels and definitely have MAC randomisation off ('Use device MAC' option selected).

    Any ideas?

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    are you using any WiFi-extenders? some of the extenders may replicate or randomize MAC addresses.

     

    0
    Comment actions Permalink
  • Avatar
    Geeklord

    No extenders. I have three wired Omada TP-Link AP's with a hardware controller.

    0
    Comment actions Permalink
  • Avatar
    FirewallaSupportDesk

    Could you try to reserve a static IP for your phones to see if it makes any different: IP Allocation?

    0
    Comment actions Permalink
  • Avatar
    Geeklord

    Thanks. I've done that for the relevant personal devices and will update in due course.

    0
    Comment actions Permalink
  • Avatar
    Geeklord

    Didn't work I'm afraid. My phone was blocked twice in the last 12 hours since setting the reserved IP

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    I suspect your phone may be randomizing MAC's still. I have opened a case, we may need to look inside

    0
    Comment actions Permalink
  • Avatar
    dagenius evil

    Hi,

    I’ve been experiencing the same issue since switching from Purple to Gold SE. I’m also using Omada hardwired APs.

    Each time I check the IP address of the device listed in the Quarantine group, it matches the IP of a device that is already connected to the network.

    So far, I’ve encountered this issue with my Pixel and two Wi-Fi cameras.

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    Quarantine is done by looking at the MAC address. Most time, if you see the same device qurantined, it is due to they are using randomized MAC 

    0
    Comment actions Permalink
  • Avatar
    dagenius evil

    MAC address randomization is disabled on all affected devices. I’ve double-checked the settings to ensure they are using their factory MAC addresses.

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    Can you record the MAC addresses of devices that keep on getting qurantined? We do know some apple devices can't turn off mac randomization (even if there is a configuration options for them)

    0
    Comment actions Permalink
  • Avatar
    dagenius evil

    the devices are still in the quarantine group, the devices are a pixel phone and ring cams

    0
    Comment actions Permalink
  • Avatar
    FirewallaSupportDesk

    Firewalla detects devices based on MAC addresses. The best would be checking what MAC addresses these devices use on Firewalla. If a devices shows up on Firewalla with different MAC addresses, check if these MAC addresses starting with the same pattern. It could be your AP is messing with MAC addresses here. 

    The easiest way to rule out is borrow/get a different AP and try again. 

    0
    Comment actions Permalink
  • Avatar
    Geeklord

    I took the opportunity to upgrade all my AP's. Since doing so it stopped. I have no idea why but my devices were mismatched, two wifi 5 and one wifi 6, and I noticed that mesh was activated that wouldn't have worked between these devices. No idea why it would suddenly start happening but that's as close as I got to figuring it out, but obviously something to do with the AP's as the controller and config is otherwise the same.

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    Are you using any "extenders"? some extenders will randomize device MAC address when they are connected via them, that can be a source of "randomizing MAC"

    0
    Comment actions Permalink

Please sign in to leave a comment.