Nice expansion of reports in the AI Protection section. Good stuff. Now I just need to learn how to best use them.
Since updating to 382 I see the new AI report that indicates a device on my network is being protected by the 2-way IPS feature. Screen shots attached of a lot of attempts to reach it. My challenge though is that I dont have a device with this MAC address that I am aware of. If I check the Mac manufacturers database for the MAC in the 2way IPS report it says Cisco.. and I have only one device made by Cisco but its mac address is different 00A:55... a VOIP ATA Spa112 as reported by the Client Status screen on the Asus RT-AC68U.
Could this be a virtual MAC from the ATA device? (have not called Cisco yet) Does the report suggest that the device is somehow inviting this activity? I turned off Bonjour on the ATA but nothing changed -the reports continue.
Is there someway for the Asus router to link the reported MAC address in the 2 way IPS report to a known device listed in the Client Status screen? One would think a Client status screen should list all the MACs and not just the h/w ones?
Thank you for any thoughts you have on this! I am certainly glad the Asus router and the Merlin FW are protecting my network.
Edward
Since updating to 382 I see the new AI report that indicates a device on my network is being protected by the 2-way IPS feature. Screen shots attached of a lot of attempts to reach it. My challenge though is that I dont have a device with this MAC address that I am aware of. If I check the Mac manufacturers database for the MAC in the 2way IPS report it says Cisco.. and I have only one device made by Cisco but its mac address is different 00A:55... a VOIP ATA Spa112 as reported by the Client Status screen on the Asus RT-AC68U.
Could this be a virtual MAC from the ATA device? (have not called Cisco yet) Does the report suggest that the device is somehow inviting this activity? I turned off Bonjour on the ATA but nothing changed -the reports continue.
Is there someway for the Asus router to link the reported MAC address in the 2 way IPS report to a known device listed in the Client Status screen? One would think a Client status screen should list all the MACs and not just the h/w ones?
Thank you for any thoughts you have on this! I am certainly glad the Asus router and the Merlin FW are protecting my network.
Edward
Attachments
Last edited: