Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    How does pfsense handle cloned mac address?

    Scheduled Pinned Locked Moved General pfSense Questions
    5 Posts 3 Posters 668 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • N
      narmenia
      last edited by

      If a user is currently online in dhcp.
      Then a new device connects but has the same mac address on a client that is currently active.

      How does pfsense handle the new client?
      Will it be given a different ip?

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        Is it in the same subnet/L2 as the first client? If so, then your switch would go nuts since that's not a valid scenario. You can't have two different devices with the same MAC. That has nothing to do with pfSense, and would have to be addressed in your AP/Switch/L2 setup.

        Even if it did manage to make a DHCP request, pfSense would most likely think it's the same client and give it the same lease, since it would be going by MAC.

        If it's on a different interface/switch/L2/subnet, that's OK and it would get an address from the other subnet.

        Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • N
          narmenia
          last edited by narmenia

          client would be on wifi.
          im offering a public "paid" wifi.

          one way people cheat is scanning for users and cloning their mac address.

          JKnottJ 1 Reply Last reply Reply Quote 0
          • JKnottJ
            JKnott @narmenia
            last edited by

            @narmenia

            If they weren't connected at the same time, there's no way to tell. However, for a paid service, you should be relying on something better than just the MAC address.

            PfSense running on Qotom mini PC
            i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
            UniFi AC-Lite access point

            I haven't lost my mind. It's around here...somewhere...

            1 Reply Last reply Reply Quote 0
            • jimpJ
              jimp Rebel Alliance Developer Netgate
              last edited by

              There isn't any way for the firewall to tell two MACs apart. You'll need something more. If it's that bad, you need L2 auth (802.1x) in your APs, not firewall controls.

              Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

              Need help fast? Netgate Global Support!

              Do not Chat/PM for help!

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.