nanog mailing list archives

Re: Eero devices expose LAN to SP during reboot


From: Mark Mayfield via NANOG <nanog () lists nanog org>
Date: Wed, 16 Sep 2026 16:18:52 -0500

Hi,

I had this experience with a Netgate 1100 at my home some time ago when its
boot storage failed, so it just became a dumb switch when powered up.  My
provider actually allowed multiple DHCP leases, so about 24 hours after it
happened I realized all my DHCP devices were directly on the Internet.

The device is based on a switch chip, so it has to boot to assign VLANs to
the ports and secure the network.


Reference:
https://docs.netgate.com/pfsense/en/latest/solutions/sg-1100/switch-overview.html

I suspect there's a lot of commodity equipment based on common chips that
may behave the same way.

Mark

On Wed, Sep 16, 2026 at 4:03 PM Brandon Martin via NANOG <
nanog () lists nanog org> wrote:

I have a customer who's Eero seems to be exposing either their entire
LAN L2 or at least several Eero MACs to the SP side consistently upon
every reboot, and given the lack of configurability that the Eero
presents, I'm at a loss to figure out how to make it not do that.

Some sources suggest this is "expected behavior" which seems baffling.
I can't imagine many SPs take kindly to having their access network
flooded with dozens of MACs all asking for addressing via DHCP on a
single access port.

Is this really "expected behavior" from a customer edge router, these
days?  If so, what's the protocol people have adopted to handle it?  The
only thing I can think of is very short MAC aging at L2 and then blindly
handing any device that shows up on the same access port the same
addresses regardless of what L2 address it purports to have.

Of course that doesn't fix the fact that any device on the customer's
network that successfully completed the DHCP exchange while the true
border Eero was "getting ready" now has unusable addressing.  Turning
DHCP lease times down low enough to combat this without the customer
noticing is pretty much a non-starter.

So what gives?

--
Brandon Martin
_______________________________________________
NANOG mailing list

https://lists.nanog.org/archives/list/nanog () lists nanog org/message/KCOYDZLREMEYSDNTG6TBFBZSO2LBBEKM/

_______________________________________________
NANOG mailing list 
https://lists.nanog.org/archives/list/nanog () lists nanog org/message/HG6PHH3AV456GFSDEFMVVCJ4TFJOYQ3U/

Current thread: