CheckEmoji Community · the emoji forum
🏠 Home 🆕 What's new ❓ Unanswered 🔥 Popular 📡 RSS Members 👥 0 online log in · register
Home › IT › IT Support › WiFi restrictions and limitations

WiFi restrictions and limitations

Started by Jack Alvarez · · 👁 6 views · 39 replies

📡 Subscribe to replies

Participants Jack AlvarezJack Cook7William Palmer7George Murphy12Maria James94
Jack Alvarez Jack Alvarez Active MemberOP
69 messages
joined Jan 2014
#1 ·
Hey there! So, I was wondering if it's actually possible to set a specific limit on how many devices can jump onto a WiFi network... like, if I wanted to cap it at exactly two specific devices that I choose, making it so absolutely nobody else can get in, even if they somehow managed to figure out the password?
Jack Cook7 Jack Cook7 Regular
376 messages
joined Aug 2017
#2 ·
Jack Alvarez said:Hey guys, is there any way to actually limit how many devices connect to my WiFi? Like, if I want to hard-set it so only two specific devices can get on, and nobody else can jump on even if they somehow guess the password?

Yeah, you can totally do that.

The easiest way is to just whitelist the specific MAC addresses of your clients right on the Access Point.
Jack Alvarez Jack Alvarez Active MemberOP
69 messages
joined Jan 2014
#3 ·
I’d really appreciate it if you could walk me through the exact steps to get this done properly
Edit🙏I actually managed to figure it out on my own in the meantime... thanks so much for the tip though!
Jack Cook7 Jack Cook7 Regular
376 messages
joined Aug 2017
#4 ·
Jack Alvarez said:Man, if you could just walk me through exactly how to pull this off, I’d really appreciate it!

I can give it a shot.

Your standard WiFi security is basically built on the WPA2 protocol—think of it as the combo of authentication and encryption. But honestly? If someone grabs your password and messes with a few settings, they’re getting in.

The easiest way to shut that down is to go into your AP and whitelist specific WiFi MAC addresses for the devices you actually want on your network.

First thing's first: you gotta hunt down those MAC addresses. Here’s how you do it:
https://kb.netgear.com/1005/How-do-I...-s-MAC-address
Usually, you can even find them slapped right on the sticker on the device itself.

Once you’ve got those addresses, hop into your AP configuration. This part gets a little tricky depending on what hardware you're running. Here’s an example using a NETGEAR setup:
https://kb.netgear.com/000053884/How...ACL-in-Insight

Don't worry about setting up a whole RADIUS server; you just need the physical Local ACL (Local access) list.
Just pop open that window and type in the addresses you want to let through.

There’s also an "inverse" way to do it—a Deny list—if you specifically want to block one annoying device from connecting.

Found this older article too. They usually call it MAC filtering, or sometimes people refer to it as a "lockdown."
https://www.techrepublic.com/blog/wi...t-in-10-steps/

And here’s the reverse trick, if you want to force a client to connect to one specific AP when they see multiple options.
https://superuser.com/questions/2651...ic-mac-address

Fair warning though: MAC filtering isn't bulletproof. Check out the downsides here:
https://www.howtogeek.com/204458/why...-wi-fi-router/

Bottom line? Don't rely solely on a MAC ACL. You absolutely need to have WPA2-PSK (PreShared-Key) running alongside it.
Jack Alvarez Jack Alvarez Active MemberOP
69 messages
joined Jan 2014
#5 ·
I managed to track it down... once you log into the router settings, just head over to the wireless section and look for the WLAN MAC Filter option. From there, you can just plug in the specific MAC addresses you want to authorize, and that’s really all there is to it!
William Palmer7 William Palmer7 Member
36 messages
joined Jul 2019
#6 ·
If you're actually serious about that, then please don't
Jack Cook7 Jack Cook7 Regular
376 messages
joined Aug 2017
#7 ·
The bottom line is this:

Jack Cook7
Watch out—MAC filtering isn't the bulletproof shield you think it is.
https://www.howtogeek.com/204458/why...-wi-fi-router/

Look, don't just rely on a Local ACL. You absolutely have to pair it with WPA2-PSK (PreShared-Key) if you actually want some protection.

Sure, this setup looks fine for a basic home network. But let's be real—even WPA2 can get cracked pretty fast if someone's really trying.
William Palmer7 William Palmer7 Member
36 messages
joined Jul 2019
#8 ·
It looks like there's a way around this after all.

As for cracking the passphrase? Well, that just depends on how strong it is.
Jack Cook7 Jack Cook7 Regular
376 messages
joined Aug 2017
#9 ·
William Palmer7 said:Whether the passphrase can be cracked? Depends.

It really all comes down to what kind of password someone actually typed in.

But I’m talking about the actual WPA2 protocol itself, not just some guy setting his password to "12345678."

I was saying the same thing about WEP—it took those self-proclaimed "experts" four whole years to "fix" it after some Russian mathematician realized within seconds that the whole thing was full of holes.

Using MAC lockdown is just a little extra helper for when you're dealing with something more serious and want to put an extra limit on who can jump on the network.

The real question, though, is if you're running WPA2, whether the Mac WiFi client's MAC address is even visible to a sniffer.

If you're relying solely on a MAC filter, that's amateur hour. Literally anyone with even a tiny bit of sniffing knowledge can bypass that in sixty seconds flat.
William Palmer7 William Palmer7 Member
36 messages
joined Jul 2019
#10 ·
, if this isn't about the password itself but rather a design flaw that "relatively quickly" and reliably breaks WPA2, then we're looking at something else entirely. As far as I know, it hasn't been made public yet.
Jack Cook7 Jack Cook7 Regular
376 messages
joined Aug 2017
#11 ·
Alright, let's just kick off a whole new thread about WPA2 and what actually goes into it.

By the way, does anyone actually know why Cisco dropped support for PSK on their VPN client like ten years ago? Was it L2TP/IPsec, IPsec, or what? And don't even get me started on the issues with going through NAT.
William Palmer7 William Palmer7 Member
36 messages
joined Jul 2019
#12 ·
Sorry, I can't read minds.
Jack Cook7 Jack Cook7 Regular
376 messages
joined Aug 2017
#13 ·
Not me.

But hey, I can definitely quote this:

Jack Cook7
Just because it's there doesn't mean WPA2 can't be cracked pretty fast.


William Palmer7
, if it has nothing to do with the password and we're talking about a design flaw that "relatively quickly" and reliably "breaks" WPA2. Either way, it isn't public knowledge yet.

The differences are obvious.
Jack Alvarez Jack Alvarez Active MemberOP
69 messages
joined Jan 2014
#14 ·
Thanks for the heads-up, though honestly, this might actually work out in my favor by helping me limit my teenager's WiFi access... My main goal is to keep the home network running for all our other devices, but I want to make sure she can't just hop online with her iPhone whenever she feels like it... Or maybe there's a more sophisticated way to handle this? Essentially, what I'm thinking is that she'd have to somehow "crack" the router's password to change settings or figure out which MAC addresses are whitelisted so she could spoof them on her iPhone (is that even doable?). She isn't exactly a tech wizard when it comes to this kind of stuff, though she did manage to use Google to hunt down the WiFi password on a connected laptop because she needed it for school

Android + Tapatalk
Jack Cook7 Jack Cook7 Regular
376 messages
joined Aug 2017
#15 ·
Jack Alvarez said:Thanks for the heads-up, but honestly, this might actually help me limit my teenager's WiFi access... my goal is to have WiFi running for everything else in the house, but I don't want her jumping on it with her phone... unless there's a smarter way to do it. Basically, I figured she'd have to "crack" the router password to change settings or somehow sniff out which MAC addresses are allowed so she could spoof them on her iPhone (is that even doable)? She’s not exactly a tech wizard, but she did manage to Google how to find the WiFi password on a laptop that was already connected because she needed it for school

Android + Tapatalk

😂

Way to go, kiddo! 👍 (We're all rooting for the future internet guru whose evil dad is trying to stifle her genius 🤣 )

Look, we're talking about two totally different security concepts here.

1. First, you've got whoever manages the router itself and where they do it from. That's administrative access to the hardware.

2. Then you've got who has permission to actually use the router to get onto the internet (and how much). That's basically the passage rights dictated by the person in category #1.

So, you're really looking at at least two layers of security:
- admin-level
- user-level

There's more to it, but I won't bore you with the long version.

MAC filtering is just one tiny piece of the puzzle, and I'm not even sure if it's actually what you're looking for.
Jack Alvarez Jack Alvarez Active MemberOP
69 messages
joined Jan 2014
#16 ·
Jack Cook7 said:Way to go to the young lady! 👍 (We’re all rooting for the future tech genius whose potential is being stifled by her overly protective dad 🤣 )

Development?! What kind of development? Is she just perfecting her skills at using TikTok, Instagram, and Snapchat filters?

I manage my home router from a PC, and honestly, a teenager could probably crack it... my router password looks something like this...(kA2g+@Q*6u5)...just 13 random characters thrown together...
The only people who can get in are whoever has access to that specific PC on the LAN, plus two laptops via WiFi that have their MAC addresses specifically whitelisted.
If my teenager manages to bypass all that and hop onto our WiFi, I'm pretty sure even the WiFi at the Pentagon wouldn't be considered secure.

Android + Tapatalk
William Palmer7 William Palmer7 Member
36 messages
joined Jul 2019
#17 ·
Jack Cook7 said:Not me either.

But I can certainly quote this:

The differences are pretty obvious.

So, what exactly are you trying to get at?
Anyway.
I know what you meant about WPA2—it's definitely possible to crack it within a reasonable timeframe.
Jack Cook7 Jack Cook7 Regular
376 messages
joined Aug 2017
#18 ·
Jack Alvarez said:Development?! What kind of development? Mastering the art of those TikTok, Instagram, and Snapchat filters?

I manage my router from a PC that even a teenager could crack... my router pass looks something like this...(kA2g+@Q*6u5)... just 13 totally random characters...
The only ones getting in are whoever has access to the LAN via that specific PC, plus two laptops on WiFi with their MAC addresses whitelisted.
If my kid manages to break through that and hop on the WiFi... man, I don't think even the WiFi at the Pentagon would be safe.

Android + Tapatalk

Did you seriously just blast your router admin password out to the entire internet, or did my eyesight just go from "blurry" to "completely blind"? 😁
Jack Cook7 Jack Cook7 Regular
376 messages
joined Aug 2017
#19 ·
William Palmer7 said:Alright, so what exactly are you trying to get at here?
Whatever.
I know what you mean about WPA2—it can be cracked pretty reliably if you've got the time.

Moving away from that for a second, I’m just saying there’s a fundamental design flaw in WPA2.

I’ve made the same calls on plenty of other stuff too (SSH, RSA, etc.), but nobody ever listens to me. Then, once everything hits the fan, suddenly everyone forgets what they said before and starts acting like a total pro on "the latest security trends."
William Palmer7 William Palmer7 Member
36 messages
joined Jul 2019
#20 ·
There have always been snake oil salesmen in this industry.

You must log in or register to reply here.

Log in Register

🔗 Similar threads