Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    MAC Randomized feature of IOS and Android 10 activated as Default

    Scheduled Pinned Locked Moved DHCP and DNS
    11 Posts 4 Posters 1.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • JKnottJ
      JKnott @tejas
      last edited by

      @tejas

      Set the connections to use the hardware MAC for your SSID. You can do that with Android, but I haven't tried with iPhone. Also, with Android, even when a random MAC is used, it retains the random number for future connections to that SSID.

      PfSense running on Qotom mini PC
      i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
      UniFi AC-Lite access point

      I haven't lost my mind. It's around here...somewhere...

      T 1 Reply Last reply Reply Quote 0
      • MikeV7896M
        MikeV7896
        last edited by MikeV7896

        iOS 14 works the same way... the random MAC is saved and reused per-SSID. It does not change every time a device re-connects to the network. Of course, if the network is forgotten and re-added, the random MAC might change when re-added. It can be disabled on a per-SSID basis in the settings for that network on the device. So if you have multiple SSIDs, it would need to be disabled for each of them.

        If each of your access points has a different SSID, you could end up with one device that has reserved multiple IP addresses on your network. If all have the same name, that shouldn't happen. I don't think mesh vs non-mesh would matter here... it's the network name that matters.

        For example, I have an iPhone and Apple Watch. I go in and out of my home with my phone and watch multiple times a day, yet both only have one (new) IPv4 address each since iOS 14/WatchOS 7 were released. They don't change every time I disconnect/reconnect. If I were to forget and re-add my home WiFi, then it would likely change and I'd get a different address.

        The S in IOT stands for Security

        JKnottJ 1 Reply Last reply Reply Quote 0
        • JKnottJ
          JKnott @MikeV7896
          last edited by

          @virgiliomi

          Or just turn off Private Address for that SSID.

          PfSense running on Qotom mini PC
          i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
          UniFi AC-Lite access point

          I haven't lost my mind. It's around here...somewhere...

          MikeV7896M 1 Reply Last reply Reply Quote 0
          • MikeV7896M
            MikeV7896 @JKnott
            last edited by MikeV7896

            @JKnott said in MAC Randomized feature of IOS and Android 10 activated as Default:

            @virgiliomi

            Or just turn off Private Address for that SSID.

            Right, which is something every user would need to do on their own device (for each SSID, if there are multiple). And they'd need to remember to do it again if they were to forget and re-add the network.

            I would think from a network management perspective, having each AP with the same SSID and key would be a lot easier, both on the user side and on the admin side.

            The S in IOT stands for Security

            JKnottJ 1 Reply Last reply Reply Quote 0
            • T
              tejas LAYER 8 @JKnott
              last edited by

              @JKnott said in MAC Randomized feature of IOS and Android 10 activated as Default:

              @tejas

              Set the connections to use the hardware MAC for your SSID. You can do that with Android, but I haven't tried with iPhone. Also, with Android, even when a random MAC is used, it retains the random number for future connections to that SSID.

              Didn't knew, that the Android retains the same random MAC for SSID.

              JKnottJ 1 Reply Last reply Reply Quote 0
              • JKnottJ
                JKnott @MikeV7896
                last edited by

                @virgiliomi said in MAC Randomized feature of IOS and Android 10 activated as Default:

                I would think from a network management perspective, having each AP with the same SSID and key would be a lot easier, both on the user side and on the admin side.

                Are they not the same? If not, that's nuts. I don't recall if the OP mentioned.

                PfSense running on Qotom mini PC
                i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                UniFi AC-Lite access point

                I haven't lost my mind. It's around here...somewhere...

                MikeV7896M 1 Reply Last reply Reply Quote 0
                • JKnottJ
                  JKnott @tejas
                  last edited by

                  @tejas

                  Yep, just Google on android random mac for info.

                  PfSense running on Qotom mini PC
                  i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                  UniFi AC-Lite access point

                  I haven't lost my mind. It's around here...somewhere...

                  1 Reply Last reply Reply Quote 0
                  • MikeV7896M
                    MikeV7896 @JKnott
                    last edited by MikeV7896

                    @JKnott said in MAC Randomized feature of IOS and Android 10 activated as Default:

                    Are they not the same? If not, that's nuts. I don't recall if the OP mentioned.

                    They didn't mention... just said there were 5 routers used in access point mode. But the only way I could see running out of DHCP addresses is if they're each a different name, giving each device up to 5 IP addresses on the network, one for each SSID.

                    The S in IOT stands for Security

                    JKnottJ 1 Reply Last reply Reply Quote 0
                    • JKnottJ
                      JKnott @MikeV7896
                      last edited by

                      @virgiliomi

                      Actually, if he has 5, perhaps he should be using proper access points. Some of those are intended for such use and make for a much smoother transition between APs.

                      PfSense running on Qotom mini PC
                      i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                      UniFi AC-Lite access point

                      I haven't lost my mind. It's around here...somewhere...

                      1 Reply Last reply Reply Quote 0
                      • bingo600B
                        bingo600
                        last edited by

                        Or just turn off Private Address for that SSID.

                        Just upgraded to 14.2 , and had to disable private address om my iPhone/iPad
                        Nice feature , that you can do it per SSID šŸ‘

                        /Bingo

                        If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

                        pfSense+ 23.05.1 (ZFS)

                        QOTOM-Q355G4 Quad Lan.
                        CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
                        LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.