I'd upgraded PC-cillin last month and wondered why their firewall didn't complain when I connected to a different network than my normal wireless one. So looked at the firewall settings; it detected my gateway IP (and it's not a NATed address) but didn't pick up the MAC address. Strange, because arp -a displays it fine. The "bigged-up" by marketing "Wi-Fi" detection facility wouldn't enable either. So I thought I'd email them and ask why it didn't work.

Hi folks,
1) The firewall does not pick up the MAC address from the router, even though it's in the ARP cache. This means that I could run the risk of just relying on IP addresses on wireless networks and the gateway may have the usual address for NATed gateways.
2) WiFi detection complains it does not support the current network.
NIC is Atheros AR5001X+ Wireless Network Adapter

Those who know me will probably be shocked that this was a nice email, don't be, I started off at 18 being the general technical support person for an electronics firm. I still remember how people treat tech support monkeys. Be nice people, it's not a fun job. Anyway the first reply arrived;

Unfortunately some network configuration are not read and the Wi-fi does not support certain secure Configuration, It does not support bridging and NAT

I don't use NAT, my ISP kindly gives me a /28 and I have a firewall running transparently between the router and the rest of the network. There is a wireless bridge, but that's not between this machine and the router although of course an access point is. So I replied

OK but my network is not NATed or bridged, unless you're counting a wireless access point as a bridge, which it really isn't. As I can see the arp cache using arp -a surely you can get at it too. Are you saying that because I use WPA you can't enable the network scanning either? Frankly that sounds rather lame, as again surely it's a matter of pinging up and down the netmask and reading the arp cache for mac addresses?

Ok, I'm getting a little sarcastic here. The response to this is brilliant though;

WPA is not supported either

Try to use wep and see if you get better results

So lets get this straight, Trend release a new system, talking up the wireless intrusion detection, it doesn't work with WPA and the advice is to step down to broken WEP? Oh dear. If anyone has managed to get their firewall profile switching working in a useful way (and not triggering when I connect to a VPN which seems to be the only time I see the prompts) please let me know how.