Hi,
Just installed the 4.9.0 release on flint 2 and appreciate the simplified parental controls. However there are 2 legacy parts missing from the new feature set that were indispensable for me:
- Entering a profile device by mac address - I used the parent controls to lock inconsiderate devices from acquiring unwanted updates, sharing personal files and allowing indirect access to the web for my kids (I’m looking at you qnap). There would be no way no for me to specify the device before it connects and wreaks havoc on my carefully protected, static configuration in the 4.9 parental controls.
- Disable internet access for devices without a profile. Related to the above, very useful for mass blocking iot or cloud connected devices before appropriate configuration. This feature allowed for connection to the network (via the allow list feature that I also use), but blocks the internet connection for the device while I configure it.
Related post Deny new clients from connecting
I would hope these features can be added in future updates, as pre-configuring firewall rules for so many devices on a home network is an onerous task.
Thanks for reading
Hi,
Sorry for the late reply.
And thank you for your suggestion.
We'll discuss it with our product team to see whether these features can be added back in a future release.
In the meantime, could you clarify why the Allowlist feature doesn't meet your requirements?
Well simply put the devices in this use case are those that need access to the network, but before they are connected, they should be allocated to a parental control group (using their mac address) before they gain internet access. Due to the way these devices are configured for limited user control this cannot be accomplished on the device itself. The allowlist feature alone will not accomplish this easily.
The way I do this is to browse the system log in lucy to find the denial ack message containing the mac address of the device not on the allowlist, then add the mac to the parental control group manually before the device is identified on the network.
The additional point regarding blocking unlisted devices is a no brainer. If a device is not in a parental control group, it has full internet access. My kids know how to spoof mac addresses.. and how to get other device addresses from the local ARP tables… I only find out when I see conflicting ip address allocation in the logs.
(also sorry for the very late reply. I have been re-making my network topology after an upgrade and am here to get the flint 4 but missed my chance apparently, and update on availability has been requested elsewhere if you can bump that along would be much appreciated :).
Edit: I need more coffee to make my brain work
Hi,
Thank you for the further clarification. We will discuss this with our product team.
Regarding Flint 4, the pre-order options should still be available at the moment:
However, please note that if you are located in the US region, all options will appear as unavailable due to the following:
Flint 4 will not be available in the U.S. during this pre-order phase due to recent FCC-related developments in the United States concerning networking products. For more details, please refer to our official statement: GL.iNet Statement on Recent FCC Regulatory Developments.
Ty for the reply, and the consideration. I was able to pre-order the flint 4 yesterday! Only the super early birds went before I could get one.
I am not based in the US thankfully.
Cheers,
Nick
1 Like