A real job from summer 2026, anonymised. A rural business in East Sussex, security alerts on two desktops, and a piece of consumer networking kit behaving exactly as designed, which was the problem.

The Problem

Both desktop computers at a rural business started raising repeated security alerts from our managed ESET protection: warnings about ARP cache poisoning, MAC spoofing and duplicate IP addresses. Alerts like that can indicate someone attacking the network, so they cannot simply be dismissed. At the same time, connectivity around the property was not reliable.

Diagnosis

On site, we reviewed the network address tables on the affected machines. One device on the network was answering for multiple addresses at once, including the broadband router itself. In other words, something on the LAN was impersonating the router, which is precisely the behaviour the security software is designed to flag.

The culprit was not an attacker. A recently added consumer Wi-Fi range extender, running in its default extender mode, was rewriting device addresses as it relayed traffic between its radios. To the security software on the desktops, that address rewriting is indistinguishable from a spoofing attack. As set up, the extender also risked creating a network loop, because it had been cabled into the same network it was wirelessly extending.

The Fix

The extender was reconfigured from extender mode into access point mode, using a wired connection back to the router as its uplink, and its Wi-Fi name and password were set to match the main network so devices roam between the two seamlessly. That removed the wireless relaying that caused the address rewriting. The relevant detections were then tuned on the two desktops so the previous false alarms would not recur.

The Outcome

The alerts stopped, the impersonation pattern cleared from the network tables, and both machines stayed online throughout the work. The business also got a written recommendation for the longer term: if coverage across multiple buildings needs to grow, proper access points with wired backhaul are the right tool, not a chain of consumer extenders.

What This Illustrates

Two things. First, security alerts deserve investigation, not dismissal: these were false positives, but proving that required looking at the actual network tables rather than guessing. Second, Wi-Fi extenders in their default mode cause more subtle problems than most people expect. If your network misbehaves after adding one, the extender is a prime suspect. Our network setup and troubleshooting service covers exactly this kind of diagnosis, and our guide to WiFi that keeps dropping covers the checks you can do yourself first.