Firewall Wizards mailing list archives
Re: Blocking at firewall via MAC address
From: black () galaxy silvren com
Date: Fri, 14 Dec 2001 12:07:49 -0500 (EST)
Blocking via a MAC address is pointless, unless the laptop is directly attached to your firewall. Remember, MAC addresses are LOCAL to the segment, they do not travel across networks! If you have: Wkstn A <----> Router <----> Wkstn B The only MAC you will see at Wkstn A is the mac address of the router's interface -- not Wkstn B! On Thu, 13 Dec 2001, B. Scott Harroff wrote:
A business parter has a security requirement that only pre-identified and approved laptops (identified by MAC address acting as a physical token) can access a network behind a firewall. Identification and blocking by IP address alone is not acceptable as it could be too easily changed by a user to match the IP address of an approved machine. This could be done by placing a smart switch that only allows cerain MAC's on certain ports to communicate with the firewall. The other (cost preferable) option would be to have the firewall block communications from all but machines with approved MAC and IP addresses. Does anyone have a soltion on how to block via MAC address with OpenBSD? _______________________________________________ firewall-wizards mailing list firewall-wizards () nfr com http://list.nfr.com/mailman/listinfo/firewall-wizards
_______________________________________________ firewall-wizards mailing list firewall-wizards () nfr com http://list.nfr.com/mailman/listinfo/firewall-wizards
Current thread:
- potential network attacks Daniel Handley (Dec 13)
- Blocking at firewall via MAC address B. Scott Harroff (Dec 14)
- Re: Blocking at firewall via MAC address Patrick Darden (Dec 15)
- Re: Blocking at firewall via MAC address Paul Robertson (Dec 16)
- Re: Blocking at firewall via MAC address black (Dec 15)
- Re: Blocking at firewall via MAC address B. Scott Harroff (Dec 15)
- Re: Blocking at firewall via MAC address Stephen P. Berry (Dec 16)
- Re: Blocking at firewall via MAC address Mark Brown (Dec 17)
- Re: Blocking at firewall via MAC address R. DuFresne (Dec 16)
- Re: Blocking at firewall via MAC address B. Scott Harroff (Dec 16)
- Re: Blocking at firewall via MAC address Ryan McBride (Dec 17)
- Re: Blocking at firewall via MAC address Paul Cardon (Dec 17)
- Re: Blocking at firewall via MAC address David Lang (Dec 17)
- Re: Blocking at firewall via MAC address Patrick Darden (Dec 15)
- Blocking at firewall via MAC address B. Scott Harroff (Dec 14)
- Re: Blocking at firewall via MAC address Patrick Darden (Dec 17)