macOS blocks local network access
Since macOS 15, an app needs the Local Network permission before it may talk to devices on your local network. KLSTR.ctrl talks to every KLSTR.one fixture and Art-Net node over the local network, so without that permission it sees nothing. macOS asks for the permission the first time KLSTR.ctrl tries to reach the network. The permission can also get stuck: macOS then refuses everything KLSTR.ctrl sends although the switch in System Settings looks right. This has been seen right after the IPv4 address of the lighting interface was changed, while KLSTR.ctrl was running.
How you recognise it
- A message in the top right corner, Local network access is blocked, says that every send on your interface is refused by the operating system. It has an Open Privacy & Security button and stays until the problem is gone.
- The Health Check tab shows a finding under system › localNetwork › denied that
starts with Every local send on followed by the interface name, for example
en7. - The Log has a warning that starts with
[KLSTR] cannot send on. - KLSTR.one fixtures show offline, or never appear, although the cable is fine and the status dot next to KLSTR.one in the header is green.
- Art-Net nodes can disappear too. KLSTR.ctrl raises no finding for them.

On first launch: allow access
The first time KLSTR.ctrl connects to an interface, macOS asks whether KLSTR.ctrl may find and connect to devices on your local network. Allow it. If you refused, or closed the question without answering, KLSTR.ctrl stays blocked until you switch the permission on, as described below.
Switch the permission off and on again
Open the Local Network settings
Click Open Privacy & Security in the Local network access is blocked message. It opens System Settings › Privacy & Security. Click Local Network.
If the message is gone, open System Settings › Privacy & Security › Local Network yourself.
Toggle KLSTR.ctrl
Find KLSTR.ctrl in the list. Switch it off, then on again. If it was off, switching it on is enough.
Restart the computer if it still fails
If the message and the finding don't go away within a few seconds, restart the computer. KLSTR.ctrl can't lift the block itself: rebuilding its connection doesn't help while macOS refuses it.
What you should see
- As soon as KLSTR.ctrl receives the first message from a KLSTR.one fixture again, the Local network access is blocked message and the Health Check finding disappear by themselves.
- KLSTR.one fixtures come back online in the Network Topology within seconds.
- Art-Net nodes reply to the next ArtPoll again.
The message and the finding only clear when a KLSTR.one fixture is actually heard. With no KLSTR.one fixture powered on and connected to the interface, they stay, even when the permission is fixed. Selecting the interface again clears the finding, and you can close the message yourself.
How KLSTR.ctrl notices
Every few seconds, KLSTR.ctrl sends a small test message to the KLSTR.one multicast group on the selected interface and expects to hear it back. Fixtures ignore it. When even that send is refused by the computer (the system reports the network as unreachable), KLSTR.ctrl knows the block is on the computer, not on the network, and raises the message and the finding once per connection.
Plain unreachable devices look different: the send works, the fixtures just don't answer. For that case, see Devices are not discovered.
If something goes wrong
| What you see | Likely cause | What to do |
|---|---|---|
| The message and the finding stay after you toggled the permission | macOS still blocks KLSTR.ctrl, or no KLSTR.one fixture is connected to tell KLSTR.ctrl that it works again | Check that a KLSTR.one fixture is powered on and connected. Then restart the computer |
| The message comes back after you changed the interface's IP address | The block can come back when the network settings change while KLSTR.ctrl runs | Toggle the permission off and on again |
| No message, no finding, but no device appears | Not a permission problem | See Devices are not discovered |
| The same message on Windows, without the macOS advice | The operating system or security software refuses every send on that interface | Check the firewall and any network security software on the computer |
Related
Written for KLSTR.ctrl 1.2.0 (a0df909) · Checked 1 Oct 2026
Devices are not discovered
What to check when KLSTR.one fixtures, Art-Net nodes or the RDM fixtures behind them don't show up in KLSTR.ctrl.
The topology view looks wrong
Why fixtures show up in a group box, in the wrong order or after they were removed from the Device Topology, and how to get a correct picture of the DMX line again.