NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
train_wreck
May 28, 2016Luminary
FVS336G changes WAN MAC address based on connectivity - how to disable this?
There is a highly annoying feature of this router I would like to disable. When the router loses internet connectivity, it appears to change its WAN MAC address to a "dummy" address of "00:de:ad:xx:x...
Danthem
May 30, 2016NETGEAR Employee
That doesn't sound right and might indicate a hardware issue with the WAN port (or on ISP device), some units do this to indicate an error (https://en.wikipedia.org/wiki/Hexspeak#Notable_magic_numbers).
Are you sure it's coming from the FVS? No other device connected? Can you do a packet capture from the WAN side of the FVS and verify that the source MAC address on frames coming from the FVS? You can do WAN packet captures from Monitoring -> Diagnostics.
- train_wreckMay 31, 2016Luminary
Yes, I'm fairly sure it is coming from the FVS; those MACs only show up on the modem when the FVS is connected (and, incidentally, show up in the ARP tables of other devices connected to the switch that the modem, FVS and other devices are connected to). The MACs show up even when connected directly to the modem. I am unable to do a capture on the device, since the MACs only show up when the FVS can't pull an IP, and at that point when I try to do a packet capture the FVS complains that "The interface is down" & won't let me trace. I will try using port mirroring on a switch to see if I can capture the FVS traffic that way.
- train_wreckMay 31, 2016Luminary
One thing I did find while browsing around the CLI: There are references to the de:ad address on the loopback interface. Here is the output of "util routing_table_ipv6":
::1/128 :: U 0 0 1 lo fc00::/128 :: U 0 0 2 lo fc00::1/128 :: U 0 0 1 lo fe80::/128 :: U 0 0 2 lo fe80::/128 :: U 0 0 2 lo fe80::/128 :: U 0 0 2 lo fe80::2de:adff:fe10:7500/128 :: U 0 0 1 lo fe80::2de:adff:fe10:7501/128 :: U 0 0 1 lo
Note the IPv6 loopback has numerous addresses, one of which has the exact same value as the MAC address listed in the modem screenshot (00:de:ad:10:75:00). As to why a loopback address on the FVS is showing up in the ARP tables of other devices..... no idea.
- train_wreckMay 31, 2016Luminary
Another development: with port mirroring enabled, a packat capture on the mirrored port shows the following IPv6 broadcast packets send from the FVS:
02:00:42.820407 de:ad:de:ad:de:af > 33:33:00:00:00:02, IPv6, length 70: fe80::2de:adff:fe10:7500 > ff02::2: ICMP6, router solicitation, length 16 02:00:46.820232 de:ad:de:ad:de:af > 33:33:00:00:00:02, IPv6, length 70: fe80::2de:adff:fe10:7500 > ff02::2: ICMP6, router solicitation, length 16 02:00:50.820144 de:ad:de:ad:de:af > 33:33:00:00:00:02, IPv6, length 70: fe80::2de:adff:fe10:7500 > ff02::2: ICMP6, router solicitation, length 16
Related Content
NETGEAR Academy

Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology!
Join Us!