NETGEAR EX6100 no internet with MAC ACL enabled on router

b_rassmonk

Commendable
Oct 2, 2016
2
0
1,510
Netgear EX6100 MAC ACL issues with my router SOLVED

PROBLEM: Can't connect to internet using EX6100 in combination with W111v2 or other wireless adapter and routers.

FIX FOR NETGEAR EX6100 using a MAC ACL on your ROUTER.

IMPORTANT NOTES, OPINIONS, TESTING AND GENERAL B1TCH1NG:

PROBLEM DISCLAIMER: This particular solution may not work for you if you have different configurations between Windows, your router, your extender or adapter, I'm not responsible for figuring that out, you are responsible for reading the below guide and gleaning the necessary info that you need.

NOTE: Everybody wants to blame the NETGEAR W111v2 wireless adapter for the connection issues. This hardware actually works great, this hardware is not the problem. So FYI, the W111v2 is not the problem, it is how your EXTENDER talks to YOUR ROUTER.

NOTE: Don't EVER bother calling your ISP techs, those guys are not that good at all and will NEVER be able to figure out this problem
NOTE: References in this review:
1. Adapter (I'm referring to my Wireless NETGEAR W111v2) that is
plugged into the computers USB port
2. Extender (I'm referring to my Wireless NETGEAR EX6100 Extender)
3. Router (I'm referring to my (Arris) Motorola Surfboard 612x series)
a. Notes: I don't have my firewall enabled on this (Don't need to, I already
have 2 firewalls anyway) and if I have MAC ACL lists enabled, I'm not worried anyway
b. I am using WPA2-PSK for my Wireless Encryption
NOTE: Microsoft will not be able to help you
NOTE: This was written from a high level, if you don't understand this, I'm sorry,
I'm not going to explain this at a newb level because I went through
H3ll trying to get the MAC ACL's to work in this setup and I'm not going to spoon feed

NOTE: In this setup choose to let windows manage your wireless adapter connection
after you finish installing your wireless adapter

NOTE: This walktrhough will work for any inter combination of Wireless adapters and routers,
the only thing that matters in this case is the extender

NOTE: If you have a ISP owned router/modem I can't help you with that because that
means this probably doesn't apply to you because it is likely you don't know how
this stuff works because any reasonable IT person will NEVER rent a router
from an ISP, that would just be stupid! In addition the ISP Hardware has A LOT
of stuff locked down.

NOTE: When I refer to VMAC's, it is only in refernce to the devices that are connected
to the EX6100 You may very well have devices without VMAC's and only
the RAW MACS in your routers ACL already.

NOTE: DO NOT SET STATIC IP's YOU DO NOT NEED TO

NOTE: LET WINDOWS MANAGE YOUR WIRELESS CONNECTION, DO NOT LET
NETGEAR DO THIS I'VE SEEN (POSSIBLE) THAT NETGEAR'S SOFTWARE
DOESN'T PLAY NICE WITH WINDOWS WIRELESS THIS I HAVEN'T CONFIRMED
THOUGH, JUST CHOSE THE EASY / SAFE WAY TO MANAGE MY WIRELESS
CONNECTION I believe it has something to do with the way WINDOZE manages
the wireless connections.

TEST: Take your WIFI adapter, install it, get your connection working then uninstall it completely
and then repeat the process and you will notice that windows will increment that
connection by 1 and keep doing it for everytime you uninstall the adapater and reinstall
it, I have not found ANY way to remove the incremented connection,s I've scoured the
net for it and found nothing, that would take a windows engineer to tell you the answer,
MY BET IS THAT IT IS kept in the Registry! I've tried the Net Use command, in additon
to the command that allows you to see and remove ghosted or unused items in the
device manager but I do not agree with what others have said about deleting the
hidden / ghosted items, they may still be used and I'm a Linux man, Windows is just so
I can use Battlenet and Steam and get the best out of my graphics card, You can do
this Linux side but it is to big of a pain so I just host a dual boot windows / mint.
When I was troulbeshooting this at times I've noticed Windows will try to connect to
(Let's say your SSID is MYCONNECTION)
MYCONNECTION and MYCONNECTION 2 or MYCONNECTION 3 all at the same time
using the same DHCP IP and AT that time you will get a DHCP IP conflict and I believe
this issue occurs when you let NETGEAR manage your connection as I've only noticed
that behavior when I let NETGEAR mange the connection. Lastly like I said, I chose the
safe route, I haven't fully tested this regarding Windows vs. Netgear managing the
connection, my main concern was getting the MAC ACL working for security reasons.
Now that I got it to work using the instructions below, I could care less about proving this,
by all means, go ahead if you want to. It would be extremely interesting to determine how
to remove the incremented connections. I'm putting my money on the registry though as
I believe it is getting soruced from there.

NOTE: These instrcutions are my intellectual property only in reference to the corporation
/ company/ business known as NETGEAR. That company being the same company
that produced / labeled the hardware I reference in this review / tech walk through.
If the referenced company NETGEAR takes / steals my solution to udpate their
documentation it is illegal on their behalf to do so, they have to pay me for my work.
However I do offer this up to the public sphere with no obligations in any direction or
guarantees of any sort. In my determination the public sphere include all persons and
websites that are not associated with the referenced company NETGEAR in any business
sense but to exclude those persons or sites that would host these instructions on
NETGEAR's behalf in any fashion and the limitation of useage also applies to any
of NETGEAR's websites whatever they may be named. To sum up that limitation,
no persons or business entities associated with NETGEAR may use this information
in any way.
That said, I'm pissed off at NETGEAR for making go through this h3ll!!
The hardware is actually quite good! The software isn't bad either, the instructions....
A monkey could've provided better instructions for getting the EX6100 to work with
your MAC ACL.

THE FIX:
1. You have to update to the latest firmware on the EX6100
a. Netgears instructions are wrong about flipping the 11th or 7th (I don't remember
the bit number) bit of the 1st HEX octet of the MAC because the 3rd octet is also flipped
and you only get to see that when you upgrade to the new firmware. The old firmware
doesn't let you see the VMAC.
2. After the firmware upgrade, do a factory reset
NOTE: YOU ABSOLUTELY NEED TO UPGRADE THE FIRMWARE OR YOU WILL NEVER
BE ABLE TO SEE THE CORRECTLY BIT FLIPPED VMAC FOR YOUR EX6100 EXTENDER
TO ADD TO YOUR ROUTER
3. Now you can setup the extender and then acquire the devices 2.4GHz Virtual MAC
NOTE: This is the staw that broke the camel's back. I researched this for a LONG TIME
before I was able to figure this out because it makes no sense at all
a. LOg into the extender and router
i. NOTE: At this point your router's MAC ACL SHOULD BE DISABLED
b. You will see the EX6100's VMAC, put that in your router's MAC ACL.
i. It will be the MAC starting with the first bit flipped on the 1st octet but remember
this is the same VMAC that has the 3rd HEX octet flipped as well, you'll notice
NETGEAR's documentation says NOTHING about the 3rd octet being different at
all, MORONS, PIECES OF SH1T!!!!
c. If you only put this VMAC in the your router's ACL you'll notice that 1/3rd of the time you'll
get a connection but it will drop in a little time and you won't be able to connect to the router.
It may even tell you that you have an internet connection but you still won't be able to
connect to anything. Hwever sometimes it does work but only for short periods of time.
You should also note this has NOTHING NOTHING NOTHING NOTHING to do with DHCP IP
conflicts or Signal loss or Static IP's (unless you set a static IP, if you did, set it back to
DHCP) or device drivers or letting windows manage your adapter or letting NETGEAR
manage the connection.
i. I did ipconfig /release and renew and disabled the wireless adapater and uninstalled it and
reinstalled it many times trying to figure this out. I looked at the event and error logs on
the router as well as a last resort (leaving out a LOT of trouble shooting)
and I fingally figured out what the problem was.
BTW: I used various softwares such as Angry IP and Wireshark for analysis and that one
software Xperia or something that has a wireless network troubleshooter.
None of them helped me NONE of them. This one you just had to know enough to figure
it out on your own
d. In order to make a MAC ACL work on your router with the EX6100 you need 2 MAC's
from the extender
i. NOTE: I'm not saying I'm correct about the 2 MAC's, I haven't experimented further by taking
the A6 MAC out of the routers MAC ACL because I think I need it anyway and as stated I
could be worng about this but here is my theory, the A6 MAC is the actual Hardware's MAC
for the EX6100 and the 2nd MAC is the one that is actually tied to the 2.4GHz band
that allows you to have a DHCP IP. The 2nd MAC was very difficult to find, here is how
I found it.
e. Now that you've put the A6 MAC in your router (WITH THE MAC ACL STILL DISABLED) you'll
notice the typical VMAC devices that are connecting to the router...you'll see your A6 MAC
but it WILL NOT HAVE AN IP (or the SSID of the Extender) but then I was looking through the
list of currently connected devices and then guess what, I saw the SSID of the EX6100 and
GUESS BLEEPING WHAT!!!! There is a 02:0F:B5:XX:XX:XX VMAC that is tied to the SSID
of the EX6100 and that is the 2nd MAC THA HAS THE BLEEPING IP!!! NETGEAR
NEVER MENTIONS THIS BECAUSE THEY ARE FUCKING IDIOTS.
As far as I know, I'm the only one that made this work EVER!
NETGEAR's own support doesn't even know how this thing works. I've called them, they
don't know shit about this thing!!! That information is also nowhere to be found in ANY of
their documentation. They do tell you to add the EX6100's VMAC to the routers ACL but
they also classify the bit flipped VMAC from the back of the router as the VMAC for the
device and they never EVER mention that the EX6100 will also have a
02:0F:B5:XX:XX:XX MAC address.
4. Connect your Devices to the NETGEAR EX6100
5. Now that you've added the 2 EX6100 VMAC's, put all your RAW MACS and other device
Virtual MACs from the EX6100 into your routers ACL
6. Connect and DONE!