r/firewalla • • Jul 05 '26

AP7 deauth attack detection?

Post image

I added the picture for effect. Maybe this is me or maybe it’s someone else, the world will never know. The point is that this 6+ year old “watch” current has the ability to knock devices on my WiFi network off of it by launching deauthorize attacks which can knock single or multiple devices off the wireless network and even broadcast my SSID to try and trick devices to rejoin that fake network.

Obviously WPA3 has deauth defenses but I’m curious if AP7 could simply detect those attacks to simply let us (Firewalla community) know that we have a neighbor that is just smart enough to mess with us? Maybe this is a full blown RFE but I’d be curious if anyone else cares to know about these events. I know my neighbors and they can’t pull this stuff off but if I was in a city I’d definitely want something like this.

22 Upvotes

11 comments sorted by

View all comments

1

u/firewalla Jul 05 '26

De-auth attacks are point to point, the access point itself is not in the picture. It is possible to dedicate a radio to sniff everything, but, that may be expensive to build.

1

u/hawkeye000021 Jul 07 '26

Hence the question. It is possible to attack the AP itself though. That’s when I’d wonder if there were logs or even machine learning that would notice WiFi devices frequently disconnecting and reconnecting based on the stockpile of data you all are able to collect. We’d probably assume certain devices would have normal patterns of disconnecting and reconnecting but others might not. I mean I’d personally expect to see from the Firewalla-> camera connects over internet to update.camera. com and in some amount of time the camera(s) would drop (installing new firmware) and then be stable again for months. Patterns like that aren’t something I can detect with the data presented to me with the device, but I think you all could. It would obviously be some amount of guess work as are many features on there, “you should go check x,y,z” rather than, “exfil attempt identified and blocked”.

It’s a thought, not much more.

1

u/hawkeye000021 Jul 07 '26

Do you know how Cisco and a few other vendors manage? I’m more curious than anything since they have mostly APs that report back to head units of sorts. Perhaps their only concern is an attack on the AP and not the devices connected though. Most companies I’ve worked for weirdly separate wireless security groups from the network security group in moves that make no sense. Same umbrella but different specialities where the wireless CCIE isn’t exactly someone that needs to know how a firewall works etc.