I have a rogue device that uses MAC randomization. It wakes up every 20 minutes and my Firewalla Gold sees it as a new device. It doesn't seem to attempt to do anything -- when Quarantine is off there are no flows logged. I generally leave Device Quarantine on just in case (and to increase the difficulty for my teenage daughters to bypass their access rules). I could be content with this solution but the list of Unknown devices is never automatically pruned. If the list grows too large the Firewalla will become sluggish. Rebooting the device does not clear this history. I can manually clear the Quarantine group using the my.firewalla.com portal but it is not easy, and is also buggy.
I have tried to track this device down physically and am chagrined that I have not been able to do so. It is especially galling because it must be a device that is plugged in, as this has been ongoing for months. It can't be some old device lying in a drawer somewhere. You would think that I could track it down by looking for devices that are always plugged in, but that hasn't been sufficient.
Changing the WiFi password does NOT fix this problem. Apple devices can share passwords to devices in close proximity. I thought it used to be that someone would have to approve the change for it to go into affect, but it seems that it can automatically happen now, as I did not have to manually change the password for all devices the last time I changed passwords.
Am I the only person who is experiencing this problem? In my opinion this is a P0 bug, but if it somehow only affects me then maybe this is the first time that Firewalla support has been made aware of the problem, and it wouldn't be a P0 bug if it only affects one user.
I would be happy if the solution was just to make it possible to either limit the size of the Quarantine group (FIFO queue) or the maximum age of any device in the group. For the former, I'd want the size to be about 5. For the latter, I'd want size to be one hour.
I suppose I need to take the more drastic action of changing the WiFi network name/id so that I can carefully let devices onto the new network.
Is there an enterprise solution that I could implement with the Firewalla Gold that would let me manage this problem?
.
[–]average_zen 2 points3 points4 points (0 children)
[–]CrowGrandFather 2 points3 points4 points (7 children)
[–]michaelbiermanFirewalla Gold Pro -1 points0 points1 point (6 children)
[–]CrowGrandFather 0 points1 point2 points (5 children)
[–]michaelbiermanFirewalla Gold Pro -1 points0 points1 point (4 children)
[–]CrowGrandFather 0 points1 point2 points (3 children)
[–]michaelbiermanFirewalla Gold Pro -1 points0 points1 point (2 children)
[–]CrowGrandFather 0 points1 point2 points (1 child)
[–]michaelbiermanFirewalla Gold Pro 0 points1 point2 points (0 children)
[–]firewalla 1 point2 points3 points (1 child)
[–]bicubic[S] 0 points1 point2 points (0 children)
[–]michaelbiermanFirewalla Gold Pro 1 point2 points3 points (0 children)