Re: [pfSense Support] MAC Filtering

2009-02-22 Thread apiase...@midatlanticbb.com
They are not all on the same broadcast domain, as Cisco and my other equipment provides a way for separating user to user traffic without using vlans. That being said i still get all broadcasts to the pfSense, as this is the only box all the users can talk to, so yes i do see 1000+ arp entires.

Re: [pfSense Support] MAC Filtering

2009-02-21 Thread Chris Buechler
On Fri, Feb 20, 2009 at 3:20 PM, apiase...@midatlanticbb.com wrote: > I guess my real goal is that anywhere a IP address can be used in pfSense, a > MAC address could be used also, but the MAC address would simply be replaced > with whatever it's IP is in the arp table. Of course some things like

Re: [pfSense Support] MAC Filtering

2009-02-20 Thread apiase...@midatlanticbb.com
I guess my real goal is that anywhere a IP address can be used in pfSense, a MAC address could be used also, but the MAC address would simply be replaced with whatever it's IP is in the arp table. Of course some things like the LAN IP, ect would not work this way. Mostly talking about the Fire

Re: [pfSense Support] MAC Filtering

2009-02-20 Thread Gary Buckmaster
RB wrote: On Fri, Feb 20, 2009 at 07:13, Gary Buckmaster wrote: pfSense does not do firewalling based on MAC address. Actually, it does, if indirectly. Use the captive portal. More than likely it fits your use case anyway, but can also be used to enter static lists of allowed MAC ad

Re: [pfSense Support] MAC Filtering

2009-02-20 Thread RB
On Fri, Feb 20, 2009 at 07:13, Gary Buckmaster wrote: > pfSense does not do firewalling based on MAC address. Actually, it does, if indirectly. Use the captive portal. More than likely it fits your use case anyway, but can also be used to enter static lists of allowed MAC addresses that do not

Re: [pfSense Support] MAC Filtering

2009-02-20 Thread Gary Buckmaster
MAC address filtering is of extremely limited utility. It is just as trivial to spoof a MAC address as it is to spoof an IP address. The problems you are trying to solve are already solved with captive portal and a judicious use of DHCP. If you require further layers of obtuseness, you can e

Re: [pfSense Support] MAC Filtering

2009-02-20 Thread apiase...@midatlanticbb.com
Yeah, I was hoping to get around that, by simply adding the MAC address to a firewall rule, and pfSense would check the ARP table and use the appropriate IP address automatically. So i guess it's not true layer 2 filtering, but its close enough. Adam Tim Nelson wrote: MAC to IP address tra

Re: [pfSense Support] MAC Filtering

2009-02-20 Thread Tim Nelson
MAC to IP address tracking is handled by the ARP package. :-) All joking aside, maybe you want to look at static DHCP assignments denying unknown clients or the captive portal? Tim Nelson Systems/Network Support Rockbochs Inc. (218)727-4332 x105 - apiase...@midatlanticbb.com wrote: > Are t

Re: [pfSense Support] MAC Filtering

2009-02-20 Thread apiase...@midatlanticbb.com
Are there any plans on adding this feature, or MAC to IP Address tracking. I would be willing to submit an bounty if it's technically possible. This is very useful for hotels, airports, & wifi hot spots. Where you want to block an PC that is using DHCP. I've actually never seen this feature

Re: [pfSense Support] MAC Filtering

2009-02-20 Thread Gary Buckmaster
pfSense does not do firewalling based on MAC address. Quirino Santilli wrote: Hello guys, I need to build a bridging firewall with MAC address based rules. Is pfsense capable of doing the trick? If not (as I guessed from the features) how can I achieve my goal? Thank you for the he

[pfSense Support] MAC Filtering

2009-02-20 Thread Quirino Santilli
Hello guys, I need to build a bridging firewall with MAC address based rules. Is pfsense capable of doing the trick? If not (as I guessed from the features) how can I achieve my goal? Thank you for the help. r3N0oV4