cancel
Showing results for 
Search instead for 
Did you mean: 
Replies are disabled for this topic. Start a new one or visit our Help Center.

Restrict Wifi access by MAC address

dave8775
Community Member

I have looked at the other threads' responses on this topic and I simply can't understand why that would be the case, specially when this feature exists in most routers (including the telco provided ones).   If I restrict WiFi access by known MAC addresses then only those specific MAC addresses can join the network.  As for ease of use, the router could very well alert/notify on attempts to join the network (good password) by a new device (just as it does today) and only allow access once that device's MAC address is added to the ACL (by the admin).  Since in a home network you own the devices that connect, you can easily change the device's WiFi config to not use randomized MAC addresses.

Can someone technical please explain why this is not being added to Google Router?

As for, why is this needed?  Because I am tired of login in to my home network and not recognizing devices connected to it.  I don't run a coffeeshop.  I want to explicitly control which devices can connect to my home network and I don't want any unknown (including MAC randomized) devices to connect, period.

Please add this feature to your routers.  You don't have to make it a default use case, but at least allow those of us that wish to know what devices connect, and are authorized to connect, to enable it.  That way, even if a house member knows the WiFi password, he/she can't add a new device without it being explicitly approved.

4 REPLIES 4

Meski
Community Member

It's less secure than you might think.   This explains why.

https://superuser.com/questions/19383/why-is-mac-based-authentication-insecure

I don't work for Google, but this could be why they don't do it 

 

dave8775
Community Member

Thanks for the link!  Yes, security is always a tradeoff to "effort to hack".  That said, despite the fact that a "hacker" can sniff the traffic and spoof the MAC--such hacker would still have to know the WiFi password--on the plus side you'd be able to know which devices can/are connected to your network.

Jeff
Community Specialist
Community Specialist

Hey dave8775,

 

Meski provided some good info that explain some of the security design choices. I can see how MAC address filtering would be convenient for your situation, however. What I can do is pass your comments along to our internal teams in the form of a feature request. Aside from that, is there anything else I can help you with?

 

Thanks,
Jeff

Jeff
Community Specialist
Community Specialist

Hi all,

As we got our resolution here, I'm going to mark this one as resolved in the next 24 hours. Thanks to all who helped and contributed. If anyone has any other needs, please feel free to let me know before the lock.

Thanks,
Jeff