Hi, I had this experience with a Netgate 1100 at my home some time ago when its boot storage failed, so it just became a dumb switch when powered up. My provider actually allowed multiple DHCP leases, so about 24 hours after it happened I realized all my DHCP devices were directly on the Internet. The device is based on a switch chip, so it has to boot to assign VLANs to the ports and secure the network. Reference: https://docs.netgate.com/pfsense/en/latest/solutions/sg-1100/switch-overview... I suspect there's a lot of commodity equipment based on common chips that may behave the same way. Mark On Wed, Sep 16, 2026 at 4:03 PM Brandon Martin via NANOG < nanog@lists.nanog.org> wrote:
I have a customer who's Eero seems to be exposing either their entire LAN L2 or at least several Eero MACs to the SP side consistently upon every reboot, and given the lack of configurability that the Eero presents, I'm at a loss to figure out how to make it not do that.
Some sources suggest this is "expected behavior" which seems baffling. I can't imagine many SPs take kindly to having their access network flooded with dozens of MACs all asking for addressing via DHCP on a single access port.
Is this really "expected behavior" from a customer edge router, these days? If so, what's the protocol people have adopted to handle it? The only thing I can think of is very short MAC aging at L2 and then blindly handing any device that shows up on the same access port the same addresses regardless of what L2 address it purports to have.
Of course that doesn't fix the fact that any device on the customer's network that successfully completed the DHCP exchange while the true border Eero was "getting ready" now has unusable addressing. Turning DHCP lease times down low enough to combat this without the customer noticing is pretty much a non-starter.
So what gives?
-- Brandon Martin _______________________________________________ NANOG mailing list
https://lists.nanog.org/archives/list/nanog@lists.nanog.org/message/KCOYDZLR...