Connecting to n-devs-smb.tplinkcloud.com AND n-deventry-smb.tplinkcloud.com - UNACCEPTABLE
My OPNSense FW is blocking connection back to
n-devs-smb.tplinkcloud.com
n-deventry-smb.tplinkcloud.com
This is unacceptable to have this calling home and it looks like using smb across the internet, clearly unsafe and since I don not use cloud based is a breach in GDPR since I have not authorised said software from connecting to these domains. Also looks like developer entry points!!
Please advise that this will be taken out on the next firmware upgrade or of required, then only those whom choose to use cloud based solution\updates and so forth.
- Copy Link
- Subscribe
- Bookmark
- Report Inappropriate Content
For anyone who comes across this thread at a later date, a packet capture running for several hours from a location prior to the NATing element on my network appears to confirm what @Fae was indicating -- that the reported controller upgrades have resolved the issue as indicated.
With the packet capture, I was able to isolate the queries and traffic to the TP-Link cloud hosts were originating from user end point devices on the network -- users who had the Kasa app on their mobile devices connected via wifi. I saw no connection attempts to TPLink's cloud servers from the Omada Software Controller itself while my packet capture was running.
It is certainly possible that I simply didn't have the packet capture running at the time when the Software Controller would have phoned home, but based on the amount of traffic I've been seeing, it seems like the true traffic source has been accurately identified.
- Copy Link
- Report Inappropriate Content
- Copy Link
- Report Inappropriate Content
Skavoovie wrote
I see no settings in Maintenance similar to what you describe -- only "Backup & Restore", "Auto Backup", and "Export for Support" sections. This is the Ubuntu DEB file image.
I have clicked through every possible link in the entire interface multiple times on multiple occasions -- any setting that is remotely connected to something outside my local network or is a cloud-related setting has always been disabled.
What other settings can I review or change?
You've already get all settings. Sorry to mention that the screenshot I provided previously is based on Controller 5.7. It seems that you're using Controller 5.8 or later version, so it's found at Settings > Controller Settings. I've edit my previous reply with the controller version.
- Copy Link
- Report Inappropriate Content
@Fae I don't find the menu to stop data collection is it normal?
Thanks!
- Copy Link
- Report Inappropriate Content
Hello @PascalM,
If you are using Omada Controller v5.8 or later version, as mentioned in my last reply:
In Global View, go to Settings > Controller Settings to disable Controller / Devices Update Notification at User Interface, and find Allow Data Collection at the very bottom and toggle it off, then Save.
- Copy Link
- Report Inappropriate Content
Thanks @Fae ! I had an old firmware version on my OC200, that's why I could not see the toggle off data collection button.
- Copy Link
- Report Inappropriate Content
The only tp-link related devices I have is a Deco Mesh X50 in a home environment and a few camera's that are not plugged in at the moment
There's nobody home, and there's literally nothing noteworthy going on on my network.
I've seen Omada being mentioned here, but I haven't heard of it before.
Look at my top user
Well, that's great
I noticed this today, and I don't know when it started, but i'm seeing one or two DNS requests per SECOND.
The only traffic on my internal network from 192.168.71.249 are SSDP requests, nothing special.
Since I started typing this post, I blocked access to one of the addresses, and in this short time, 655 requests have been blocked.
I don't mind devs having backdoors the analyse and troubleshoot (if it's safe), but this seems like suspisous behavior to me.
- Copy Link
- Report Inappropriate Content
Hi @DerpyNerd
Please visit the Deco sector and start a new thread about this. This is the business product forum and we are not familiar with the product you have.
Thanks for your understanding!
- Copy Link
- Report Inappropriate Content
Information
Helpful: 4
Views: 8775
Replies: 48