NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.

RNASguy's avatar
RNASguy
Luminary
Apr 03, 2019
Status:
New Idea

WPS lock out

There appears to be no way to lock out WPS. To allow or disallow WPS should be an admin permission. Anyone with access to the physical box could create a security risk. Visitors, cleaning personnel, and others could with the correct knowledge create a registered device on the wireless network, and at some later time from a location outside the home or office access the network. This is a major security hole. We often host large parties, and it is not possible to place the router behind locked doors.

 

Even the possible work-a-round to use Access Control is not sufficient, on page:

Advanced > Security > Access Control

What one would need is a third general rule that would be:

Block all new wireless devices from connecting.


And BTW, the header at the top of the page of this group is poorly written:

 

Access Rule: This is a general rule. You can also allow or block individual devices.

 

There are two general rules to choose from, so therefore the line should read:

 

Access Rules: These are general rules. You can also allow or block individual devices.

 

(v1.0.2.62 firmware)

2 Comments

  • michaelkenward's avatar
    michaelkenward
    Guru - Experienced User

     


    RNASguy wrote:

    There appears to be no way to lock out WPS. To allow or disallow WPS should be an admin permission.

    You don't say what device you are talking about – v1.0.2.62 firmware means nothing – but many Netgear boxes have a setting to disable WPS.

     



    What one would need is a third general rule that would be:

    Block all new wireless devices from connecting.

     

    That is also already there in most devices. Isn't that in Access Control on your device?

     

    If you visit the support pages:

     

    Support | NETGEAR

     

    you can feed in the model number and find all the documentation for your hardware.

     

    As you are asking for things that already exist on some kit, I have a strong suspicion that I may have misinterpreted what you are asking for. Tell us what device you are talking about and it may become clearer.

  • Hi michaelkenward,

     

    Thanks for you help.  OOooppppsss, off course one would need hardware ID, my mistake.

    Nighthawk X4S AC2600 4x4 DualBand Smart Wifi Router R7800

    running firmware v1.0.2.62

    I don't know if there are any hardware iterations for the R7800, but nothing on the box, case, or docs indicate a hardware version.

     

    RE: your other points:

    >> That is also already there in most devices. Isn't that in Access Control on your device?

    No it is not. See attached:

     

    >> .... but many Netgear boxes have a setting to disable WPS.

     

    No, WPS cannot be locked out, with admin priviledge only.  There is a switch on the router case, so if you have physical access to the router case you have access to the WAN WiFi. One can auto disable WPS PIN after x number of failed attempts, which I have set to "1" but it would be cleaner if the admin could just say NO to WPS.

     

    bc