Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    The simplist way to how i control people can get sevice

    Scheduled Pinned Locked Moved Captive Portal
    14 Posts 4 Posters 6.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Cry HavokC
      Cry Havok
      last edited by

      No, you can't tie it down by MAC address.  If you were desperate you could look at static ARP entries.

      1 Reply Last reply Reply Quote 0
      • A
        abd2002390
        last edited by

        thank u on reply
        i found that captive portal is very good in controlling upon mac adress and the people who i want them to have a net from my server i add thier mac adress and log without the log page and if  another one try to connect will have the login page and iam already dont assign any user and password.
        but can i add user name and password and can not authenticate expect one mac address only.  in another way user name and password for one compute and if any computer else can not login with same user name and password

        1 Reply Last reply Reply Quote 0
        • Cry HavokC
          Cry Havok
          last edited by

          Did you bother to read my response before you posted exactly the same message?

          1 Reply Last reply Reply Quote 0
          • A
            abd2002390
            last edited by

            @Cry:

            Did you bother to read my response before you posted exactly the same message?

            iam sorry but i have internet problem and i did not see ur reply first time
            and thank u at all
            could give me some idea how i will do it by static arp entries

            1 Reply Last reply Reply Quote 0
            • Cry HavokC
              Cry Havok
              last edited by

              I don't know of any way to do that within the pfSense interface, which is the only way to be certain it will work across a reboot.

              Note that it would be trivial to bypass that because it's trivial to change the MAC address of most systems.  You shouldn't assume that this will bring you any real security.  If you're really worried you should look to bridging and putting all your trusted hosts on one interface and the untrusted hosts on another.  This will increase the load on your pfSense host - by how much will depend on your network.

              1 Reply Last reply Reply Quote 0
              • A
                abd2002390
                last edited by

                i see that the best and simple way with captive portal and i add people through pass mac not user name and password
                thank u and i preciate ur help

                1 Reply Last reply Reply Quote 0
                • W
                  wonslung
                  last edited by

                  you can block by mac address and use traffic shaping by ip address

                  1 Reply Last reply Reply Quote 0
                  • GruensFroeschliG
                    GruensFroeschli
                    last edited by

                    @Cry:

                    I don't know of any way to do that within the pfSense interface, which is the only way to be certain it will work across a reboot.

                    "DHCP server" –> "LAN or whatever interface you want" --> "Static ARP"
                    The static ARP entries are tied to static DHCP assignements.

                    We do what we must, because we can.

                    Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

                    1 Reply Last reply Reply Quote 0
                    • A
                      abd2002390
                      last edited by

                      @GruensFroeschli:

                      "DHCP server" –> "LAN or whatever interface you want" --> "Static ARP"
                      The static ARP entries are tied to static DHCP assignements.

                      its the seconed method but which one is reliable from dhcp server or captive portal

                      1 Reply Last reply Reply Quote 0
                      • GruensFroeschliG
                        GruensFroeschli
                        last edited by

                        With the captive portal you can allow dynamically clients if they have an user/password.

                        The solution with the DHCP is static.
                        And i dont mean the DHCP assignements.
                        Here you essentially write the ARP table yourself!

                        So it depends on your needs.

                        We do what we must, because we can.

                        Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

                        1 Reply Last reply Reply Quote 0
                        • A
                          abd2002390
                          last edited by

                          ok thank u all
                          and i happy for all ur help

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.