Explore the guide library · Extender connection checks
Some proxy-mode extenders present a translated client identifier to the router, which affects address-based rules.

A router rule tied to a device’s MAC address may behave differently after that device joins through an extender. Some extenders use a proxy arrangement that presents a translated address upstream. The router may therefore be applying the rule to a different identifier than you expect.
Verify that the model uses this behavior
TP-Link documents virtual client MAC addresses for particular proxy-mode extender arrangements. This is not a universal description of every extender, access point or mesh system. Read the instructions for the exact model and operating mode.
Compare the relevant records
Identify the device in the extender’s client view and compare it with the router’s current connected-device list. Where the supported interface exposes physical and virtual addresses, use that mapping. Do not invent a translated address from a pattern found for unrelated hardware.
Keep the rule’s purpose intact
If the rule enforces a household schedule or organization policy, correct the identity mapping through the network owner. Do not disable access control globally to make one client work. Make the smallest authorized change needed for the intended device.
Test both connection paths
- Check the device while connected directly to the router.
- Check it while connected through the extender.
- Record the upstream identity in each case.
- Verify that the intended rule applies in both situations.
A private or randomized address on the client can introduce another identity change. Keep that separate from the extender’s own translation when documenting the result.
Recheck after configuration changes
Firmware, mode changes or moving to a different extender may affect the observed arrangement. Preserve a small record of the working mapping without posting household device identifiers publicly.
Address-based rules should also be understood within their limits; they are not a substitute for strong wireless authentication. The immediate task is to make the existing authorized policy follow the correct device through the actual topology, rather than assuming the address printed on one label is always what the router sees.
Sources and editorial notes
Sources checked 8–9 October 2026. Independent guidance and original illustrations; product comparisons use published specifications rather than hands-on benchmarks. Check the exact model, revision and regional documentation before changing settings.