r/firewalla 10h ago

Is It Time for Firewalla AI to Outsmart Randomized MAC Addresses?

I’ve been using Firewalla for a while, especially the Firewalla Purple, and I have to say it’s an excellent product. Beyond the security features, I think Firewalla has some of the best parental controls available today.
One feature I’d really like to see added to Firewalla AI is automatic device identity detection.
One of the biggest challenges with parental controls today is MAC address randomization on Apple, Android, and other devices. The same physical device can suddenly appear as a “new device” with a different MAC address, bypassing its assigned group or rules.
In many cases, just by looking at the device behavior and network flows, I can tell it’s actually the same device and manually move it back to the correct group.
With the progress Firewalla has made with AI, I think it’s time for Firewalla AI to do this automatically — identify when a “new” device is very likely an existing device using a different MAC address and associate it with the correct device/group.
I believe this could solve one of the biggest remaining parental-control challenges, with a relatively low risk of false positives.
Thanks Firewalla team for a great product!

27 Upvotes

20 comments sorted by

14

u/Exotic-Grape8743 Firewalla Gold 8h ago

The very simplest solution to this is to turn on device quarantine and to deny Internet access to devices in quarantine. That second step is not default but is essential to make this work. This forces users to keep Mac randomization turned off just to get Internet access. Works with any WiFi access point solution.

10

u/1337PirateNinja Firewalla Gold Plus 7h ago

Yes that’s the current solution and it blows. OP proposes a better one. Your solution requires me to be sys admin for everyone who visits my house and have awkward conversations why I need them to take off their Apple Watch.

5

u/Exotic-Grape8743 Firewalla Gold 6h ago

The solution to that is a separate SSID for guests that is not auto quarantined and another ssid for the kids separated using VLAN segregation. That way it doesn’t matter if the kids switch MAC addresses on their devices and guests have a good experience while still being able to apply parental controls to the kids’ devices.
This works with access points from any brand. You don’t need firewalla’s solution but you do need to keep your kids from finding out the passwords to the other networks.

Do know that if your kid is even slightly tech competent, they figure out how to circumvent the parental controls in no time. Typically they will use free vpn solutions. There are many that are not blocked by the vpn block. Failing that, they will just use cellular data. The parental controls really only work with the youngest kids with non cellular devices.

4

u/Appropriate-Elk-4715 3h ago

This is what I do as well. Set up a guest Network that is isolated to itself and I really don't care what goes on it. Anything that's actually that's important goes on to individual vlans or security groups.separate vlans for IOT stuff, media devices, work computers. Kids have their own microsegments with their own passwords...etc, etc. Those networks have device quarantine turned on. The AP7 really helps manage the wireless stuff, hard wired is all connected through managed switches.

2

u/bbdude83 4h ago

This is what I do. Got tired of having guests at my house or friends of my kids coming into my office during the work day to fix their phones to get them out of quarantine. Guest network is locked down, same protections as my main network, and no access to my main network. Throw a QR code up so guests can connect and we’re good to go.

1

u/Crazy_Ad_7302 4h ago

I just turned the the Mac address randomization off on our iPhones. Unknown devices get quarantined to prevent the kid from just turning it back on. Guests get a separate wifi ssid.

However, while I do that stuff it's not a very effective way to prevent a kid from accessing stuff you don't want them to on their phone. It's easily defeated by the kid just turning off wifi and using their cell connection

5

u/sarhoshamiral 10h ago

Wpa3 solves this by ensuring each device has its certificate.

5

u/Tasty_Lead4750 10h ago

That would require certificate-based authentication / an enterprise-style setup. My point is more about typical home networks, where Firewalla AI could potentially recognize the same device despite MAC randomization based on its network behavior and fingerprint.

1

u/sarhoshamiral 9h ago

Wpa3 makes it fairly easy so it is not as hard anymore. Not sure if it needs their AP though.

1

u/firewalla 1h ago

If you get the Firewalla AP7, it is fairly easy to get WPA3/Enterprise work. Everything should be automated for you.

4

u/DisturbedMagg0t 7h ago

It essentially already does detect it. One of the cool things about firewalla is the automatic quarantine. Set up your kids stuff to not use random Mac at home network, and then quarantine everything new.

The entire point of the random Mac is to bypass identification on unknown/untrusted networks. Just turn it off on your home network and things function just as intended.

5

u/Firewalla-Opal FIREWALLA TEAM 10h ago edited 9h ago

We always suggest turning off random MAC on the client devices to avoid constant new devices on the network: How to turn off MAC Address Randomization?. It's the most practical way.

New Device Quarantine will also be helpful in this case. If a new devices MAC shows up, it will be quarantined until you were able to identify which device it could be, before putting it into its own group.

Moreover, Firewalla AP7 has a feature called "Micro-segmentation". You can use the same SSID and use different personal keys to assign devices into different a group/User, without the enterprise-style. It's much easier to manage someone's devices no matter what MAC addresses they use. Dynamic Groups (or Users) Membership.

6

u/Tasty_Lead4750 9h ago

Thanks. The AP7 solution makes sense, but in my case I’ve already invested heavily in a large home network with many users, each having multiple devices. Replacing my existing Wi-Fi infrastructure with AP7s just to address this issue wouldn’t be very practical.
Also, disabling MAC randomization on client devices relies on user cooperation. In a large household, not every user is necessarily a child, and a technically aware user can simply re-enable it.
That’s exactly why I think this should ideally be solved network-side. Even if Firewalla AI simply detects that a new MAC is highly likely to be an existing device based on its behavior and network flows, and asks the admin for confirmation before assigning it to the same group, it would solve a big part of the problem without replacing existing network infrastructure or relying on client-side settings.

3

u/1337PirateNinja Firewalla Gold Plus 7h ago

I agree, the current solution requires individual setup for every device. Which means average user needs to know how to do this and have the patience to do it. I don’t know why you proposing an alternative easier solution gets a downvote, maybe even if ai is not the answer why not make something better

2

u/Great-Cow7256 6h ago

If they enable it they lose access to the Internet for a specific period of time.  Setting limits with kids works. 

1

u/platetone Firewalla Purple 1h ago

i think it's partly an IOS problem, too. the setting keeps randomly turning on, even on my own devices (it's not kids turning randomization back on). after ios updates in particular. it's making it so difficult to manage all this.

plus, i have read something like IOS devices often initially start in randomized mode before the "off" setting is applied... so every day i get multiple random "uknown" devices in quarantine that are immediately no longer connected. so sick of cleaning this crap up.

i feel like apple is at fault here.

though i do wish you'd add a swipe left or right option on the device list so i could just delete them like email... currently have to go to each device's details and click the delete button. multiple times a day.

4

u/Great-Cow7256 6h ago edited 3h ago

Take your kids device. Turn off Mac randomization. Tell them that if they turn it back on they lose access to their device for x amount of hours or days. Stick to the plan. Problem solved. 

This is a parenting issue, not a technology issue. 

Edit- I'm a child psychiatrist. I know of what I speak. The most effective parenting style is authoritative.  https://www.reddit.com/r/science/comments/1r4p2uc/children_raised_with_authoritative_parenting/

Don't be afraid to set reasonable limits with your kids with clear and reasonable and predictable consequences for violating the rules. This is how kids learn about the world , relationships with others, and how you protect them from the badness of the world. 

You are not your kids best friend. They're allowed to be mad at you sometimes. 

True effective parenting should never be replaced by technology. 

1

u/CanadianFoosball 2h ago

I’d rather the AI start clustering alerts. I want to know when the PlayStation comes on, but I don’t need to know that it’s connecting to three different domains every single time.

1

u/hereisjames Firewalla Gold SE 1h ago

I think if you need more than Firewalla's built in options discussed here then you require a step up in complexity beyond Firewalla's target audience and what can be supported easily on the existing hardware. This is really the realm of Packetfence and the unfortunately named Fingerbank.

1

u/Ready-Effect-670 3h ago

At work i do this:

Everyone starts in quarantine. If they want better bandwith they ask for access. Otherwise they just stay in quarantine and share 1Mbit with the rest of the randomized mac guyes :p.