• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Pass a Mac address through the firewall?

Scheduled Pinned Locked Moved Firewalling
5 Posts 4 Posters 1.3k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • A
    Andreas 1
    last edited by Jul 31, 2022, 11:48 AM

    Is it possible to let a specific Mac address pass through the firewall?

    I have several lan networks on my 4 port router,

    10.27.27.x Lan network and pfSense router
    10.29.29.x IOT network

    If I connect to the 10.29.29.x network, I cannot log in to pfSense as it is on 10.27.27.1. It's because 10.29.29.x can't reach 10.27.27.x and that's how it should be. Although it would be good if you could set it up so that my laptop could access pfSense on 10.27.27.1 when it is connected to the 10.29.29.x network.

    Now I need to connect a LAN cable between the laptop and the 10.27.27.x port on the router for it to work.

    N J J 3 Replies Last reply Jul 31, 2022, 11:50 AM Reply Quote 0
    • N
      NogBadTheBad @Andreas 1
      last edited by Jul 31, 2022, 11:50 AM

      @andreas-1 No you can’t.

      You could set a dhcp reservation for the MAC address and just allow that.

      Andy

      1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

      1 Reply Last reply Reply Quote 1
      • J
        johnpoz LAYER 8 Global Moderator @Andreas 1
        last edited by Jul 31, 2022, 11:52 AM

        @andreas-1 you understand that web gui is available on all IPs of pfsense.

        So unless you created a specific rule to block access to pfsense IP on 10.29.29.1 you could use that IP to access the gui,

        Or the wan IP as well.

        What are your rules on the IOT network?

        But as @NogBadTheBad mentions normally what you do is setup a dhcp reservation so that your laptop always gets the same IP when its on your IOT network - now you can create rules on the iot interface to allow this IP to go where you want it to go.

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.8, 24.11

        A 1 Reply Last reply Jul 31, 2022, 12:16 PM Reply Quote 1
        • A
          Andreas 1 @johnpoz
          last edited by Jul 31, 2022, 12:16 PM

          @johnpoz

          A,ha. I can login to pfSense on 10.29.29.1. It was an easy fix :)

          Thanks for the quick help!

          1 Reply Last reply Reply Quote 0
          • J
            JKnott @Andreas 1
            last edited by Jul 31, 2022, 1:45 PM

            @andreas-1 said in Pass a Mac address through the firewall?:

            Is it possible to let a specific Mac address pass through the firewall?

            No. MAC addresses are valid only on the local LAN and are never passed through a router. In fact, the entire Ethernet frame is discarded when received by the router and the IP packet is encapsulated in a new frame, with a new MAC, on the other side of the router.

            PfSense running on Qotom mini PC
            i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
            UniFi AC-Lite access point

            I haven't lost my mind. It's around here...somewhere...

            1 Reply Last reply Reply Quote 1
            1 out of 5
            • First post
              1/5
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
              This community forum collects and processes your personal information.
              consent.not_received