Skip to main content

Routers · Synology

Synology Router Can't Connect New Devices

When your Synology router rejects new phones, laptops, or smart home devices while existing gear stays connected, SRM security rules or DHCP limits are usually to blame. Here is how to audit your router settings and get new devices online.

Symptoms

  • Existing devices stay online, but new devices show 'Unable to join network'
  • New device gets stuck on 'Obtaining IP address...' indefinitely
  • Smart home / IoT devices fail during initial Wi-Fi setup
  • Devices report 'Incorrect password' even when the Wi-Fi key is typed correctly
  • SRM app displays connection blocked notifications for new MAC addresses
  • Legacy Wi-Fi devices disconnect immediately after authenticating

Quick troubleshooting

  1. Step 1

    Reboot the router and target device

    Power cycle both your Synology router and the new client device. This flushes temporary network negotiation caches and clears expired DHCP lease blocks in SRM. Wait two full minutes for the router Wi-Fi LEDs to turn solid before retrying.

  2. Step 2

    Disable Wi-Fi MAC filtering in SRM

    Log into SRM via browser (router.synology.com) or the DS router app. Navigate to Wi-Fi Connect > Wi-Fi Network > MAC Filter and temporarily set the access policy to Allow All. If your new device joins immediately, update your whitelist with its actual or randomized MAC address.

  3. Step 3

    Check and expand the DHCP IP range

    Go to Network Center > Local Network > DHCP Server. Ensure the start and end IP addresses leave plenty of open slots for new clients. If you have dozens of smart home accessories, expand the subnet mask or extend the range to prevent IP starvation.

  4. Step 4

    Separate Smart Connect bands temporarily

    Smart Connect combines 2.4GHz and 5GHz under one SSID, which confuses many setup wizards on IoT devices. In Wi-Fi Connect, disable Smart Connect or create a dedicated 2.4GHz guest network to onboard smart plugs, cameras, and legacy hardware.

  5. Step 5

    Adjust Wi-Fi security levels to WPA2-PSK

    Navigate to Wi-Fi Connect > Wireless and check your encryption standard. If set to WPA2/WPA3-Personal, try changing it temporarily to WPA2-Personal (AES). Some network cards fail to complete the initial PMK handshake when modern transition modes are enforced.

Likely causes

  • SRM Wi-Fi MAC Filter / Access Control set to deny unknown hardware addresses
  • DHCP IP address pool exhaustion on the main local subnet
  • WPA3/WPA2 Mixed Mode handshake failures on older client devices
  • Smart Connect auto-steering sending 2.4GHz-only IoT gear to the 5GHz band
  • Safe Access or Threat Prevention package flagging new device MAC signatures
  • Randomized Private MAC addresses on modern iOS/Android devices tripping security policies

What's going on

Synology routers running SRM (Synology Router Manager)—like the RT2600ac, WRX560, or RT6600ax—are known for high-end security tools that rival commercial firewalls. However, these same protection features often cause mysterious roadblocks when introducing a newly unboxed laptop, smartphone, or smart home hub to your local network.

When a Synology router rejects a new connection while existing devices function normally, the hardware radios are usually fine. The issue almost always stems from SRM strict access control policies, IP address allocation limits, or wireless encryption negotiation conflicts. If you are dealing with broader connection issues, check our general router troubleshooting guides for more tips.

Symptoms people notice

  • Existing phones and TVs work fine, but a new device refuses to connect.
  • The new device toggles between "Connecting..." and "Saved" without getting online.
  • The Wi-Fi network says "Incorrect Password" even when you double-check credentials.
  • iOS or Android devices with "Private Wi-Fi Address" enabled get dropped repeatedly.
  • 2.4GHz smart plugs fail to pass the setup stage in smartphone apps.
  • SRM Safe Access sends a notification that an unknown device was blocked.

Likely causes

  1. MAC Filter Rules: SRM's built-in access control list is set to block any MAC address not specifically added to an allowlist.
  2. DHCP Pool Starvation: The router has run out of available local IP addresses within its assigned range (e.g., 192.168.1.2 to 192.168.1.50).
  3. WPA3 Compatibility: Older Wi-Fi chips cannot properly negotiate connection with WPA3/WPA2-Personal mixed mode.
  4. Smart Connect Band Steering: The router attempts to force a 2.4GHz-only client onto a 5GHz channel during authentication.
  5. Threat Prevention or Safe Access Restrictions: Built-in Synology security packages misidentify the new device's network traffic as malicious.

Quick checks first

Before digging into deep router settings, do a few quick client-side checks:

  • Disable Private MAC / Randomization: On iOS or Android, go to the Wi-Fi details for your network and toggle off "Private Wi-Fi Address" or "Use Randomized MAC." Synology security policies often get confused when a device changes its network signature.
  • Verify Password Case Sensitivity: Synology passwords are strictly case-sensitive. Type it out in a visible text note on the device first to avoid typos.
  • Test Guest Network: Enable the Guest Network in SRM with basic WPA2 security. If the new device connects there, your primary Wi-Fi network has a security or firewall rule blocking it.

When it's a real hardware fault

While software misconfigurations cause 95% of these issues on Synology systems, actual hardware failure can occur. If the router's 2.4GHz or 5GHz radio amplifier fails internally, the network name may still broadcast, but new devices will fail to finish the physical handshake.

If no new or old devices can connect over wireless—even after a full factory reset—or if Wi-Fi LEDs remain off or flash red continuously, the wireless chipset or flash memory may be damaged. In such cases, component-level repair is rarely cost-effective compared to replacing the unit. You can research alternative hardware profiles in our router reviews section or consult Synology device information.

Soft resets vs board/panel work

Always start with soft recovery steps before considering a hardware replacement:

  • Soft Reset (SRM Restart): Reboots the router's operating system, clearing active RAM caches and releasing stagnant DHCP leases. Safe to do anytime.
  • Hard Reset (Paperclip Button): Pressing the physical reset button for 4–10 seconds restores SRM to factory defaults without erasing external storage. This strips away custom MAC filters, firewall blocks, and strict WPA3 settings that might be preventing connections.
  • Internal Hardware Work: Attempting to disassemble a router to reflow Wi-Fi chips or repair power rails requires specialized micro-soldering equipment. Because consumer router mainboards are densely packed and potted for heat dissipation, DIY board repairs are generally not recommended.

Next steps

  1. Log into your SRM panel at router.synology.com and review Wi-Fi Connect > MAC Filter.
  2. Audit your local network DHCP lease pool size under Network Center > Local Network.
  3. Turn off Smart Connect temporarily to isolate the 2.4GHz and 5GHz broadcast channels.
  4. If the router fails to retain settings or drops all wireless bands entirely, explore replacement options or dive deeper into our router troubleshooting guides.

Next steps

Try the DIY guide if you're comfortable opening the device. Still stuck? Browse related problems for similar symptoms.

Related problems

logo_footer

Stay in the loop

Get new guides, reviews, and repair news.

© 2026 LML Repair. All rights reserved.