Jack Alvarez said:Man, if you could just walk me through exactly how to pull this off, I’d really appreciate it!
I can give it a shot.
Your standard WiFi security is basically built on the WPA2 protocol—think of it as the combo of authentication and encryption. But honestly? If someone grabs your password and messes with a few settings, they’re getting in.
The easiest way to shut that down is to go into your AP and whitelist specific WiFi MAC addresses for the devices you actually want on your network.
First thing's first: you gotta hunt down those MAC addresses. Here’s how you do it:
https://kb.netgear.com/1005/How-do-I...-s-MAC-addressUsually, you can even find them slapped right on the sticker on the device itself.
Once you’ve got those addresses, hop into your AP configuration. This part gets a little tricky depending on what hardware you're running. Here’s an example using a NETGEAR setup:
https://kb.netgear.com/000053884/How...ACL-in-InsightDon't worry about setting up a whole RADIUS server; you just need the physical Local ACL (Local access) list.
Just pop open that window and type in the addresses you want to let through.
There’s also an "inverse" way to do it—a Deny list—if you specifically want to block one annoying device from connecting.
Found this older article too. They usually call it MAC filtering, or sometimes people refer to it as a "lockdown."
https://www.techrepublic.com/blog/wi...t-in-10-steps/And here’s the reverse trick, if you want to force a client to connect to one specific AP when they see multiple options.
https://superuser.com/questions/2651...ic-mac-addressFair warning though: MAC filtering isn't bulletproof. Check out the downsides here:
https://www.howtogeek.com/204458/why...-wi-fi-router/Bottom line? Don't rely solely on a MAC ACL. You absolutely need to have WPA2-PSK (PreShared-Key) running alongside it.