Blocking a persistant ip / mac address.....

Post new topic   Reply to topic    DD-WRT Forum Index -> Atheros WiSOC based Hardware
Author Message
ramblin
DD-WRT User


Joined: 03 Nov 2015
Posts: 315
Location: Florida, USA

PostPosted: Sun Sep 24, 2023 15:20    Post subject: Blocking a persistant ip / mac address..... Reply with quote
I recently setup an Amazon fire stick for a neighbor using my router. This neighbor is close enough that the firestick now logs in with my router and all attempts to stop it have been futile. The firestick has been reset, registered in his name and logs in to his router and works fine but still logs into my router as an active client. Using access restrictions I have added the ip and mac address. I tried filtering and denying both,but it still logs in and out all day. Been reading that you can write a firewall rule. Most of that info is years old and doesn't apply to the newer builds and is a little over my head anyway. Advice on how to do this.
_________________
......All GOOD here... Just Handshakes and Time Stamps !......
Sponsor
egc
DD-WRT Guru


Joined: 18 Mar 2014
Posts: 12488
Location: Netherlands

PostPosted: Sun Sep 24, 2023 15:42    Post subject: Reply with quote
Change wifi password and reboot the router?
_________________
Routers:Netgear R7000, R6400v1, R6400v2, EA6900 (XvortexCFE), E2000, E1200v1, WRT54GS v1.
Install guide R6400v2, R6700v3,XR300:https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=316399
Install guide R7800/XR500: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=320614
Forum Guide Lines (important read):https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324087


Last edited by egc on Sun Sep 24, 2023 16:31; edited 3 times in total
ho1Aetoo
DD-WRT Guru


Joined: 19 Feb 2019
Posts: 2597
Location: Germany

PostPosted: Sun Sep 24, 2023 15:56    Post subject: Reply with quote
I'm pretty sure you can "discard" Wi-Fi networks in the FireTV Stick settings.
_________________
use Pi-Hole as simple DNS-Server with DD-WRT https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=331414
VLAN configuration via GUI - 2 CPU ports (R7800, EA8500 etc) https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=334342
ramblin
DD-WRT User


Joined: 03 Nov 2015
Posts: 315
Location: Florida, USA

PostPosted: Sun Sep 24, 2023 17:03    Post subject: Reply with quote
Don't really want to change the password since I have multiple WDS Stations and a lot of devices. We have reset the firestick to default factory settings and it is registered with Amazon in his name and only has his network info in there. That should have cleared it but unlike DD-WRT you cant clear NVRAM. Is there a reason that "Access Restrictions" on my AP won't block it ?
_________________
......All GOOD here... Just Handshakes and Time Stamps !......
LizardWizard
DD-WRT Novice


Joined: 14 Jan 2020
Posts: 47

PostPosted: Sun Sep 24, 2023 17:09    Post subject: Reply with quote
Are you sure it is actually currently active or just showing the old DHCP lease? In any case. I would try these.

First change the Wi-Fi password. That should solve the problem. But to be extra sure, do these as well. Go to Wireless>MAC Filter and check Enable Filter for your current wlan. Select Blacklisted Network Clients and type in the MAC Address of the FireTV Stick. Save and Apply Settings. Then go to Services>Services and under DHCP Server Setup>Static Leases, enter the MAC Address of the FireTV Stick, give it a name and also an IP outside your normal DHCP range. Save and Apply Settings. Now for the final step, go to Access Restrictions>WAN Access and choose Deny as the filter type, choose Any for the Interface, click on Edit Filter List next to List of Clients and enter the MAC Address and the static IP that you gave it in the previous step, choose Everyday and 24 hours period. Save and Apply Settings. Reboot just to be safe.

Ain't no way it can connect now.
egc
DD-WRT Guru


Joined: 18 Mar 2014
Posts: 12488
Location: Netherlands

PostPosted: Sun Sep 24, 2023 17:09    Post subject: Reply with quote
A mac address can easily be spoofed.

If you want to be safe change password

_________________
Routers:Netgear R7000, R6400v1, R6400v2, EA6900 (XvortexCFE), E2000, E1200v1, WRT54GS v1.
Install guide R6400v2, R6700v3,XR300:https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=316399
Install guide R7800/XR500: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=320614
Forum Guide Lines (important read):https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324087
ramblin
DD-WRT User


Joined: 03 Nov 2015
Posts: 315
Location: Florida, USA

PostPosted: Sun Sep 24, 2023 17:41    Post subject: Reply with quote
LizardWizard wrote:
Are you sure it is actually currently active or just showing the old DHCP lease?

#1 Go to Wireless>MAC Filter and check Enable Filter for your current wlan. Select Blacklisted Network Clients and type in the MAC Address of the FireTV Stick. Save and Apply Settings.

#2 Then go to Services>Services and under DHCP Server Setup>Static Leases, enter the MAC Address of the FireTV Stick, give it a name and also an IP outside your normal DHCP range. Save and Apply Settings.

#3 Now for the final step, go to Access Restrictions>WAN Access and choose Deny as the filter type, choose Any for the Interface, click on Edit Filter List next to List of Clients and enter the MAC Address and the static IP that you gave it in the previous step, choose Everyday and 24 hours period. Save and Apply Settings.
Ain't no way it can connect now.


OK, It is active as it appears and disappears from the list as the firestick checks in. Remember ,firesticks don't shut off, they just sleep. #3 on your list I did exactly as you describe a few days ago with no change. Now #1 on your list I just did. Never seen that before and that might fix it, but I haven't rebooted yet which bring us to #2 on the list. So enter the firestick mac, change the IP outside my range so it can't find my router ? Explain ?

_________________
......All GOOD here... Just Handshakes and Time Stamps !......
ramblin
DD-WRT User


Joined: 03 Nov 2015
Posts: 315
Location: Florida, USA

PostPosted: Sun Sep 24, 2023 20:26    Post subject: Reply with quote
LizardWizard wrote:
Go to Wireless>MAC Filter and check Enable Filter for your current wlan. Select Blacklisted Network Clients and type in the MAC Address of the FireTV Stick. Save and Apply Settings. .



Might be to early to say but this seemed to work by itself. Only been an hour or so since I rebooted but it hasn't showed back up up.

_________________
......All GOOD here... Just Handshakes and Time Stamps !......
Dr_K
DD-WRT User


Joined: 23 Mar 2018
Posts: 445

PostPosted: Tue Sep 26, 2023 16:44    Post subject: Reply with quote
While it's good to see you have this somewhat resolved..
Knowledge to control your network is always a good thing.

I believe I know the reason for your underlying real problem...

While the exact location may very by versions &/or model stick.
Under Settings then Network, scroll down towards the bottom, then switch OFF "Save Wi-Fi Passwords to Amazon"

That's the only logical reason (In My Opinion Rolling Eyes) for your network to "magically" auto fill after a Reset to Factory Defaults.....

_________________
Location 1
R7800- DD-WRT v3.0-r53562 (10/03/23) Gateway
WNDR3400v1 DD-WRT v3.0-r35531_mega-nv64k (03/26/18 ) Access Point
WRT160Nv3 DD-WRT ?v3?.0-r35531 mini (03/26/18 ) Access Point
WRT54GSv5 DD-WRT v24-r33555_micro_generic (10/20/17) Repeater
Location 2
R7800- DD-WRT v3.0-r51855 (02/25/23) Gateway
R6300v2- DD-WRT v3.0-r50671 (10-26-22) Access Point
WNDR3700v2 DD-WRT v3.0-r35531 std (03/26/18 ) Access Point
E1200 v2 DD-WRT v3.0-r35531 mega-nv64k (03/26/18 ) Gateway(for trivial reasons)
RBWAPG-5HACT2HND-BE RouterOS-v6.46.4 (2/21/20) Outdoor Access Point
2x RBSXTG-5HPACD RouterOS-v6.46.4 (2/21/20) PTP Bridge 866.6Mbps-1GbpsLAN
Location 3
2x R7000- DD-WRT v3.0-r50671 (10/26/22) Access Points
2x RBWAPG-60AD RouterOS-v6.45.9 (04/30/20) PTP Bridge 2.3Gbps-1GbpsLAN
2x RBSXTsqG-5acD RouterOS-v6.49.7 (10/14/22) PTP Bridge 866.6Mbps-1GbpsLAN

Thank You BrainSlayer for ALL that you do & have done, also to "most" everyone here that shares their knowledge
kernel-panic69
DD-WRT Guru


Joined: 08 May 2018
Posts: 13898
Location: Texas, USA

PostPosted: Tue Sep 26, 2023 18:41    Post subject: Reply with quote
ramblin wrote:
I recently setup an Amazon fire stick for a neighbor using my router.

First mistake. Use their router. Always.
ho1Aetoo wrote:
I'm pretty sure you can "discard" Wi-Fi networks in the FireTV Stick settings.

Dr_K wrote:
While the exact location may very by versions &/or model stick.
Under Settings then Network, scroll down towards the bottom, then switch OFF "Save Wi-Fi Passwords to Amazon"

Double-tap on the easiest solution.
LizardWizard wrote:
Go to Wireless>MAC Filter and check Enable Filter for your current wlan. Select Blacklisted Network Clients and type in the MAC Address of the FireTV Stick. Save and Apply Settings.

This or whitelisting known allowed clients is all that's necessary to block access. Using this for temporary DD-WRT-powered APs set up at a location while we work on planning out all the network upgrades and requirements for a building under construction.

_________________
"Life is but a fleeting moment, a vapor that vanishes quickly; All is vanity"
Contribute To DD-WRT
Pogo - A minimal level of ability is expected and needed...
DD-WRT Releases 2023 (PolitePol)
DD-WRT Releases 2023 (RSS Everything)

----------------------
Linux User #377467 counter.li.org / linuxcounter.net
Display posts from previous:    Page 1 of 1
Post new topic   Reply to topic    DD-WRT Forum Index -> Atheros WiSOC based Hardware All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum