Troubleshooting

macOS blocks local network access

Recognise and fix the macOS Local Network permission problem that makes KLSTR.one fixtures show offline although they are reachable.

Since macOS 15, an app needs the Local Network permission before it may talk to devices on your local network. KLSTR.ctrl talks to every KLSTR.one fixture and Art-Net node over the local network, so without that permission it sees nothing. macOS asks for the permission the first time KLSTR.ctrl tries to reach the network. The permission can also get stuck: macOS then refuses everything KLSTR.ctrl sends although the switch in System Settings looks right. This has been seen right after the IPv4 address of the lighting interface was changed, while KLSTR.ctrl was running.

This page is mainly about macOS. KLSTR.ctrl only detects the problem on the KLSTR.one interface, because that is where it checks its own connection all the time (see ).

How you recognise it

  • A message in the top right corner, Local network access is blocked, says that every send on your interface is refused by the operating system. It has an Open Privacy & Security button and stays until the problem is gone.
  • The Health Check tab shows a finding under system › localNetwork › denied that starts with Every local send on followed by the interface name, for example en7.
  • The Log has a warning that starts with [KLSTR] cannot send on.
  • KLSTR.one fixtures show offline, or never appear, although the cable is fine and the status dot next to KLSTR.one in the header is green.
  • Art-Net nodes can disappear too. KLSTR.ctrl raises no finding for them.

On first launch: allow access

The first time KLSTR.ctrl connects to an interface, macOS asks whether KLSTR.ctrl may find and connect to devices on your local network. Allow it. If you refused, or closed the question without answering, KLSTR.ctrl stays blocked until you switch the permission on, as described below.

Switch the permission off and on again

Open the Local Network settings

Click Open Privacy & Security in the Local network access is blocked message. It opens System Settings › Privacy & Security. Click Local Network.

If the message is gone, open System Settings › Privacy & Security › Local Network yourself.

Toggle KLSTR.ctrl

Find KLSTR.ctrl in the list. Switch it off, then on again. If it was off, switching it on is enough.

Restart the computer if it still fails

If the message and the finding don't go away within a few seconds, restart the computer. KLSTR.ctrl can't lift the block itself: rebuilding its connection doesn't help while macOS refuses it.

What you should see

  • As soon as KLSTR.ctrl receives the first message from a KLSTR.one fixture again, the Local network access is blocked message and the Health Check finding disappear by themselves.
  • KLSTR.one fixtures come back online in the Network Topology within seconds.
  • Art-Net nodes reply to the next ArtPoll again.

The message and the finding only clear when a KLSTR.one fixture is actually heard. With no KLSTR.one fixture powered on and connected to the interface, they stay, even when the permission is fixed. Selecting the interface again clears the finding, and you can close the message yourself.

How KLSTR.ctrl notices

Every few seconds, KLSTR.ctrl sends a small test message to the KLSTR.one multicast group on the selected interface and expects to hear it back. Fixtures ignore it. When even that send is refused by the computer (the system reports the network as unreachable), KLSTR.ctrl knows the block is on the computer, not on the network, and raises the message and the finding once per connection.

Plain unreachable devices look different: the send works, the fixtures just don't answer. For that case, see Devices are not discovered.

If something goes wrong

What you seeLikely causeWhat to do
The message and the finding stay after you toggled the permissionmacOS still blocks KLSTR.ctrl, or no KLSTR.one fixture is connected to tell KLSTR.ctrl that it works againCheck that a KLSTR.one fixture is powered on and connected. Then restart the computer
The message comes back after you changed the interface's IP addressThe block can come back when the network settings change while KLSTR.ctrl runsToggle the permission off and on again
No message, no finding, but no device appearsNot a permission problemSee Devices are not discovered
The same message on Windows, without the macOS adviceThe operating system or security software refuses every send on that interfaceCheck the firewall and any network security software on the computer

Written for KLSTR.ctrl 1.2.0 (a0df909) · Checked 1 Oct 2026

Copyright © 2026