Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Using pfsense as a wifi gateway

    Scheduled Pinned Locked Moved Wireless
    6 Posts 3 Posters 4.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      tommyboy180
      last edited by

      Hi,
      I have several wireless APs that are deployed in a small business. Currently each AP filters MACs on the AP itself. I want to find a solution where I can have one system sitting between my APs and my trusted network to filter the MAC address for me. This way I don't have to type one MAC into 16 different APs.

      Is it possible to use pfsense to filter MACs when passing traffic from one interface to another?

      -Tom Schaefer
      SuperMicro 1U 2X Intel pro/1000 Dual Core Intel 2.2 Ghz - 2 Gig RAM

      Please support pfBlocker | File Browser | Strikeback

      1 Reply Last reply Reply Quote 0
      • I
        ipfftw
        last edited by

        Captive portal can do pass through mac authentication. Maybe that would work for you? Not sure why you would use mac filtering and not a key, certificate or password based approach.  what are you trying to achieve?

        1 Reply Last reply Reply Quote 0
        • T
          tommyboy180
          last edited by

          I am trying to create a simple device that just filters MACs. This pfsense box might also fun havp and squid. The reason I don't want to use certificates or password based auth with RADIUS is because some devices connecting don't support cert or pass based auth, like maybe a Wii. Just MAC filtering would simply provide the security i am looking for.

          The APs could use other security. I was looking at the pf commands for MAC blocking and couldn't find anything that is Nativity support in the stable release of pfsense. I could do it with ip tables and create a web GUI for it, but again I would like pfsense. Maybe someone has done this before with something else like IPCop?

          -Tom Schaefer
          SuperMicro 1U 2X Intel pro/1000 Dual Core Intel 2.2 Ghz - 2 Gig RAM

          Please support pfBlocker | File Browser | Strikeback

          1 Reply Last reply Reply Quote 0
          • dotdashD
            dotdash
            last edited by

            FreeBSD 7.1 added mac blacklisting via arp(8), so this would be available (from the command line) in the 1.2.3 snapshots. There is also arp white or blacklisting via wlan_acl (see ifconfig) for wireless interfaces. I suspect that no one has bothered to add these to the gui due to the fact that MAC addresses are easily spoofable.

            1 Reply Last reply Reply Quote 0
            • T
              tommyboy180
              last edited by

              An excellent solution dotdash.
              Perhaps I could take a look at a snapshot and contribute a WebGUI for MAC filtering?

              -Tom Schaefer
              SuperMicro 1U 2X Intel pro/1000 Dual Core Intel 2.2 Ghz - 2 Gig RAM

              Please support pfBlocker | File Browser | Strikeback

              1 Reply Last reply Reply Quote 0
              • dotdashD
                dotdash
                last edited by

                You could either create a diff and send it to someone on the core team, or create a git clone and submit the changes for review. You would just need to add an interface for the mac: commands and maybe have the wireless status also show the list mac output.

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.