Orbi WiFi 7 RBE973
Reply

Orbi Pro Security: What is better MAC ACL or Enable Access Control???

DH_1
Apprentice

Orbi Pro Security: What is better MAC ACL or Enable Access Control???

Hello Again,.

 

I have a very simple network setup....Router - Satillite.

3 SSID 1. For Admin. 2. Staff 3. ioT.  Total about 20 devices connenting.  Pretty simple and straightforward.

 

cuurently for Security, MAC ACL is diabled on all SSID.

Access Control is also, Not enabled......

 

And so far, Have not any issues.  Everyone/everything connects and no issues.

 

My onlly concern is I am seeing a lot of DoS Attacks/Scans...

Here is a sample..

DoS Attack: SYN/ACK Scan] from source: 95.217.31.46, port 443, Sunday, September 26, 2021 19:44:38
[DoS Attack: SYN/ACK Scan] from source: 95.217.31.46, port 443, Sunday, September 26, 2021 19:29:41

 

so I am not sure what is the better for security...

 

I am not a techy person, so any help would be appreciated....

Thanks

 

 

 

Model: SRK60B03|Orbi Pro Tri-Band Business WiFi System
Message 1 of 3

Accepted Solutions
schumaku
Guru

Re: Orbi Pro Security: What is better MAC ACL or Enable Access Control???


@DH_1 wrote:

cuurently for Security, MAC ACL is diabled on all SSID.

MAC ACL is a management pain in general. You could enable it, register all MAC addresses of the device connecting to your wireless network. Then you will find overly smart devices defaulting to random MAC addresses (so tomorrow the same device won't connect again because a different MAC is used), and in two weeks you will be back wondering why the new computer, the replaced mobile phone and so on won't connect to your network anymore.

 


@DH_1 wrote:

Access Control is also, Not enabled......

As above - it just adds the a MAC based access control for the complete network, wireless and wired.

 

Both variants can be used only if you have tight management control of all your devices, can manage all your devices, have good processes for adding new devices to the network, have good processes in place for replacing existing devices, availability of network admin when you are using BYOD and your workers are coming in early morning or in the evening with a new or replaced device.

 

Never deploy more security than what you understand and what you can handle.

 


@DH_1 wrote:

My onlly concern is I am seeing a lot of DoS Attacks/Scans...

Complete different story, unrelated to the to the MAC ACL on the wireless radios and Access Control on the local network. See my reply on your dedicated thread.

 

 

View solution in original post

Message 2 of 3

All Replies
schumaku
Guru

Re: Orbi Pro Security: What is better MAC ACL or Enable Access Control???


@DH_1 wrote:

cuurently for Security, MAC ACL is diabled on all SSID.

MAC ACL is a management pain in general. You could enable it, register all MAC addresses of the device connecting to your wireless network. Then you will find overly smart devices defaulting to random MAC addresses (so tomorrow the same device won't connect again because a different MAC is used), and in two weeks you will be back wondering why the new computer, the replaced mobile phone and so on won't connect to your network anymore.

 


@DH_1 wrote:

Access Control is also, Not enabled......

As above - it just adds the a MAC based access control for the complete network, wireless and wired.

 

Both variants can be used only if you have tight management control of all your devices, can manage all your devices, have good processes for adding new devices to the network, have good processes in place for replacing existing devices, availability of network admin when you are using BYOD and your workers are coming in early morning or in the evening with a new or replaced device.

 

Never deploy more security than what you understand and what you can handle.

 


@DH_1 wrote:

My onlly concern is I am seeing a lot of DoS Attacks/Scans...

Complete different story, unrelated to the to the MAC ACL on the wireless radios and Access Control on the local network. See my reply on your dedicated thread.

 

 

Message 2 of 3
DH_1
Apprentice

Re: Orbi Pro Security: What is better MAC ACL or Enable Access Control???

Thank you @schumaku 

 

Both security options have been disabled for about 2-3 month's, and no issues.  Noone is trying to "Hack" into our network.

 

So I think I will follow your advise from below  "Never deploy more security than what you understand and what you can handle."

 

And I will leave them both in the disabled state....my only conceren was the logs showing the DoS Attack: Scan , stuff.

 

Cheers

dH

Message 3 of 3
Top Contributors
Discussion stats
  • 2 replies
  • 1175 views
  • 1 kudo
  • 2 in conversation
Announcements