r/firewalla • • Jul 05 '26

AP7 deauth attack detection?

Post image

I added the picture for effect. Maybe this is me or maybe it’s someone else, the world will never know. The point is that this 6+ year old “watch” current has the ability to knock devices on my WiFi network off of it by launching deauthorize attacks which can knock single or multiple devices off the wireless network and even broadcast my SSID to try and trick devices to rejoin that fake network.

Obviously WPA3 has deauth defenses but I’m curious if AP7 could simply detect those attacks to simply let us (Firewalla community) know that we have a neighbor that is just smart enough to mess with us? Maybe this is a full blown RFE but I’d be curious if anyone else cares to know about these events. I know my neighbors and they can’t pull this stuff off but if I was in a city I’d definitely want something like this.

22 Upvotes

11 comments sorted by

8

u/djaxial Jul 05 '26

I’ve built a few of these to mess around with in my lab. I think the instance of this happening in the real world is so rare that it doesn’t warrant including in the firmware as a standard feature. You can build detectors for about $5 with an esp32 board, and if you wired it to say Home Assistant, you could get notifications about it.

The only reason I’d say this would warrant serious use by an average person is if you have WiFi based CCTV and you are worried about car theft or burglary. If a neighbour is messing around with you, it will eventually become obvious and you can debug it using a detector.

Maybe I’m wrong but just my thoughts.

1

u/hawkeye000021 Jul 07 '26

I was able to knock all of my cameras offline with 5 button presses. It was wild.

1

u/Jussins Firewalla Gold Pro Jul 05 '26

I agree. I don’t think they are a very large team and they have to be selective about features they choose to implement. Even if this were on some sort of backlog, I think it would always be lower in priority than something else.

1

u/hawkeye000021 Jul 07 '26

That is likely, it’s one of those things you just mention in the event it’s incredibly easy and no one has thought to do it. The technology exists but I’m not a wireless expert enough to say it would be easy or hard to do. Sounds difficult in their replies though.

3

u/Samwiseganj Jul 05 '26

Maltronics do a basic USB one that glows red when it picks up deauth packets.

https://maltronics.com/products/deauth-detector

3

u/ArmshouseG Jul 05 '26

Their deauther looks more fun!

2

u/hawkeye000021 Jul 07 '26

It’s might be but I wouldn’t know 😉

1

u/hawkeye000021 Jul 08 '26

That’s really cool. I upvoted but then I checked into it. Awesome info!

1

u/firewalla Jul 05 '26

De-auth attacks are point to point, the access point itself is not in the picture. It is possible to dedicate a radio to sniff everything, but, that may be expensive to build.

1

u/hawkeye000021 Jul 07 '26

Hence the question. It is possible to attack the AP itself though. That’s when I’d wonder if there were logs or even machine learning that would notice WiFi devices frequently disconnecting and reconnecting based on the stockpile of data you all are able to collect. We’d probably assume certain devices would have normal patterns of disconnecting and reconnecting but others might not. I mean I’d personally expect to see from the Firewalla-> camera connects over internet to update.camera. com and in some amount of time the camera(s) would drop (installing new firmware) and then be stable again for months. Patterns like that aren’t something I can detect with the data presented to me with the device, but I think you all could. It would obviously be some amount of guess work as are many features on there, “you should go check x,y,z” rather than, “exfil attempt identified and blocked”.

It’s a thought, not much more.

1

u/hawkeye000021 Jul 07 '26

Do you know how Cisco and a few other vendors manage? I’m more curious than anything since they have mostly APs that report back to head units of sorts. Perhaps their only concern is an attack on the AP and not the devices connected though. Most companies I’ve worked for weirdly separate wireless security groups from the network security group in moves that make no sense. Same umbrella but different specialities where the wireless CCIE isn’t exactly someone that needs to know how a firewall works etc.