OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • General Discussion »
  • [SOLVED] Block mac address
« previous next »
  • Print
Pages: [1]

Author Topic: [SOLVED] Block mac address  (Read 18279 times)

fox983

  • Newbie
  • *
  • Posts: 47
  • Karma: 1
    • View Profile
[SOLVED] Block mac address
« on: October 11, 2015, 02:18:51 pm »
Hi, is there a way to block navigation on wan to a specific mac address? I don't find anything, eg. in firewall rule I can only set an IP address...
« Last Edit: October 13, 2015, 07:22:08 am by franco »
Logged

weust

  • Hero Member
  • *****
  • Posts: 650
  • Karma: 57
    • View Profile
Re: Block mac address
« Reply #1 on: October 11, 2015, 03:00:05 pm »
AFAIK a MAC address isn't known outside the internal network. Meaning, it's not visible on the internet?
I could be wrong though.
Logged
Hobbyist at home, sysadmin at work. Sometimes the first is mixed with the second.

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 17705
  • Karma: 1618
    • View Profile
Re: Block mac address
« Reply #2 on: October 11, 2015, 04:47:48 pm »
Packet filters normally don't allow filtering below the IP layer[1]. If you still want to do it, you will maybe have luck by modifying the ARP table manually.

[1] https://www.freebsd.org/doc/en/articles/filtering-bridges/article.html
Logged

fox983

  • Newbie
  • *
  • Posts: 47
  • Karma: 1
    • View Profile
Re: Block mac address
« Reply #3 on: October 11, 2015, 11:01:54 pm »
Inside LAN mac address is known and I think it could be possible block or allow navigation through firewall. So through GUI isn't possible to block navigation? Many domestic router have this function. It could be nice also allocate more or less bandwidth, but this is another story  ;D
Logged

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 17705
  • Karma: 1618
    • View Profile
Re: Block mac address
« Reply #4 on: October 12, 2015, 07:16:46 am »
I was thinking you could use the captive portal MAC filtering and just have no accounts active on the login page?
Logged

fox983

  • Newbie
  • *
  • Posts: 47
  • Karma: 1
    • View Profile
Re: Block mac address
« Reply #5 on: October 12, 2015, 12:02:25 pm »
Captive Portal seems working BUT I think it could be improved: if a user has internet access (without authentication) and I block his mac address, the only way is reboot the firewall, if not  PC continues to navigate. Trying to reboot Pc or Captive Portal with no success... If I reboot firewall, navigation on PC is denied.
Is it possible block navigation without rebooting?
Thank you
Logged

weust

  • Hero Member
  • *****
  • Posts: 650
  • Karma: 57
    • View Profile
Re: Block mac address
« Reply #6 on: October 12, 2015, 12:06:30 pm »
And if that person changes the MAC address?
Logged
Hobbyist at home, sysadmin at work. Sometimes the first is mixed with the second.

fox983

  • Newbie
  • *
  • Posts: 47
  • Karma: 1
    • View Profile
Re: Block mac address
« Reply #7 on: October 12, 2015, 12:45:04 pm »
Change IP is easier than change mac address, rather best known...
Obviously changing mac address or IP is the way to bypass the block.
Logged

fox983

  • Newbie
  • *
  • Posts: 47
  • Karma: 1
    • View Profile
Re: Block mac address
« Reply #8 on: October 12, 2015, 12:47:22 pm »
In Captive Portal - Allowed IP addresses is there a way to insert a range of IP instead of a single IP?
Logged

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 17705
  • Karma: 1618
    • View Profile
Re: Block mac address
« Reply #9 on: October 13, 2015, 07:21:58 am »
Not yet, but I will record this as a feature request for the all new captive portal:

https://github.com/opnsense/core/issues/430
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • English Forums »
  • General Discussion »
  • [SOLVED] Block mac address
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2