Deco is constantly trying to connect to the internet

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

Deco is constantly trying to connect to the internet

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
Deco is constantly trying to connect to the internet
Deco is constantly trying to connect to the internet
2023-06-08 19:21:26
Tags: #Access Point Mode #Firewall
Model: Deco XE75  
Hardware Version: V1
Firmware Version: 1.2.2

Hello, I only operate the three Deco XE75 as an access point. First of all, the devices work perfectly and the WLAN is very good.
However, I have a problem. If there is no solution for this, I would unfortunately have to return the devices.


I run my own DHCP server, DNS server and time server on the internal network.
Nevertheless, the master constantly tries to access the Internet. I'm running the network behind a hardware firewall and it's getting completely flooded with blocked messages from the Deco. I just want good AccessPoints and I can't understand why the device keeps trying to get to port 443 TCP (HTTPS) in "AccessPoint" mode. Access is also not just sometimes, every 2-5!!!! Seconds it tries to connect.

 

How can I switch that off and what's the point that the device in simple access point mode wants to access the Internet every two seconds? Ok for an update, but not all the time in normal operation!

 

Thanks for the help!

  0      
  0      
#1
Options
4 Reply
Re:Deco is constantly trying to connect to the internet
2023-06-08 21:07:20

  @Eldarion85 

 

TP-Link Deco mesh management is cloud-based. Your Deco app will contact TP-Link cloud servers to retrieve and update your Deco mesh configuration. Your Main Deco provides that info to TP-Link cloud in (almost) real time. 

How to verify that: turn off WiFi on smartphone with Deco app, leaving just cellular service with data. Without WiFi your Deco app will still be able to report Deco mesh status and update Deco mesh settings. Which proves that Deco app does not talk directly to Deco mesh through your LAN, but communicates with Main Deco through Internet and TP-Link servers.

 

This is by design. It is core functionality of Deco WiFi mesh which you can't switch off in Deco app settings.

  2  
  2  
#2
Options
Re:Deco is constantly trying to connect to the internet
2023-06-09 08:36:34

  @Alexandre. 

 

I can understand that about the cloud and it's true that I also have access via the app when I'm not in my own network.

 

However, I looked at the DNS requests from the Deco-Master and found that, in addition to the request for "n-devs-gw.tplinkcloud.com", many other IP addresses were also requested from the DNS server. Including Live, Google, YouTube, Amazon, Reddit and Linkedin.
And no, these requests do not come from WLAN devices, but directly from the Deco master's IP address to the DNS server. You can also see this when you look at the times that this is an automated request from Deco to the DNS server.

 

So the connection to the Internet is obviously not only used for the mash cloud. Why does the device constantly want to access the websites of the other providers?

 

DNS Server

  0  
  0  
#3
Options
Re:Deco is constantly trying to connect to the internet
2023-06-09 11:21:52 - last edited 2023-06-09 14:23:28

  @Eldarion85 

 

Main Deco uses DNS queries for Internet connectivity health check. If they fail, Main Deco may assume Internet link is down and will change LED color to red (among other things).

 

These are just DNS queries. Deco does not access these web sites after resolving host names. This is not an uncommon way to check Internet connectivity. I can't tell how popular it is, but this is not unheard of: I had WiFi router from different brand that also uses DNS queries for that same purpose.

 

This is also part of core functionality of Deco WiFi mesh which you can't switch off in Deco app settings.

  0  
  0  
#4
Options
Re:Deco is constantly trying to connect to the internet
2023-06-09 14:13:32

  @Alexandre. 

 

I checked the firewall log. In fact, all incoming messages from the Deco master for port 443 (HTTPS) only go to the IP address of "n-devs-gw.tplinkcloud.com". The other requests to the internal DNS server that I listed in the last post do not go to the firewall or gateway.

 

I can live with that. Thank you for your support!

  0  
  0  
#5
Options