• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

How to block an IP address or Mac address

Scheduled Pinned Locked Moved General pfSense Questions
8 Posts 4 Posters 3.2k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • I
    invoker
    last edited by Apr 22, 2024, 12:13 PM

    Hello sir is it possible to block an ip address from accessing the internet for example i want to block the ip of a client from the internet

    but my configuration is in DHCP is it possible or how can i block a specific IP from my network via pfsense firewall

    G 1 Reply Last reply Apr 22, 2024, 1:30 PM Reply Quote 0
    • S
      stephenw10 Netgate Administrator
      last edited by Apr 22, 2024, 12:26 PM

      Sure you can add a firewall block rule with a single IP address as the source.

      You can a DHCP static mapping to be sure that client always gets the same IP address.

      Steve

      I 1 Reply Last reply Apr 22, 2024, 12:40 PM Reply Quote 1
      • I
        invoker @stephenw10
        last edited by invoker Apr 22, 2024, 12:41 PM Apr 22, 2024, 12:40 PM

        @stephenw10

        do you have the steps sir?

        for example i static mapping the IP on a certain device it does not have an issue? even they are trying to using static IP?

        J 1 Reply Last reply Apr 22, 2024, 12:47 PM Reply Quote 0
        • J
          johnpoz LAYER 8 Global Moderator @invoker
          last edited by johnpoz Apr 22, 2024, 12:50 PM Apr 22, 2024, 12:47 PM

          @invoker There is a bit of a difference in blocking an IP, and the user of said device trying to circumvent that block by changing their IP and or mac address.

          Plus version has the new L2 filtering, so you could block on mac. But mac is also changeable, so they could always change their device mac and get a different IP then what you reserve for them, and circumvent any specific IP or mac address block.

          You could use static arp - so pfsense wouldn't even talk to their device unless it was using a specific IP and mac address. This can prevent them from changing their mac to get a different IP, etc.

          The best thing to do if you want to stop users from changing IP or mac to circumvent your rules based on those is to put them in their own vlan where doesn't matter what the source IP is or their mac address.

          Specific based rules per IP or mac are normally better suited for when you have a locked down vlan, but yet you might have a device you use on that vlan.. Say a wireless network, and you sometimes connect your phone or tablet to that wifi and what the IP you reserved for your devices to have more access than the normal vlan does. This way for someone to circumvent the rules they would have to know the specific IP that has the allow rule set for it.

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.7.2, 24.11

          1 Reply Last reply Reply Quote 0
          • S
            stephenw10 Netgate Administrator
            last edited by Apr 22, 2024, 12:49 PM

            If a device set's it own static IP address then the rule would not apply. You can set a static ARP entry so that MAC address will only work with DHCP (or statically set to the same IP). A client could still potentially spoof their MAC address though.

            1 Reply Last reply Reply Quote 0
            • G
              Gertjan @invoker
              last edited by Gertjan Apr 22, 2024, 1:30 PM Apr 22, 2024, 1:30 PM

              @invoker
              Added to what has been said above :

              This DHCP server option :

              5c922786-c6ee-4474-bca8-8e014bb1c5f5-image.png

              will only allow the DHCP server to answer to DHCP requests to know (static lease setup with a known MAC ) device.

              Then add all thehe known MAC addresses to this firewall list :

              c58f9701-b6c4-41aa-9134-2df5efec7410-image.png

              and block all the unknown "others".

              From this point on, some one can gain access only if they know the list of allowed MACs.

              The next step is far more drastic - or actually way more simple :
              "Do no allow people on your network that you don't want on your network".
              You can enforce this by 'cutting the cable' or create that 'very difficult Wifi password' and don't give it to anyone.

              Anyway, I thought all this was a non issue, but then I saw this video, and I'm still not sure if its all fake/ just a humor video :
              89498b92-4b66-4638-97a0-c792bab4eeb5-image.png

              No "help me" PM's please. Use the forum, the community will thank you.
              Edit : and where are the logs ??

              1 Reply Last reply Reply Quote 0
              • S
                stephenw10 Netgate Administrator
                last edited by Apr 22, 2024, 2:09 PM

                Yeah. 😂
                I think it's fake but it's sufficiently well done you can never be sure!

                J 1 Reply Last reply Apr 22, 2024, 3:27 PM Reply Quote 0
                • J
                  johnpoz LAYER 8 Global Moderator @stephenw10
                  last edited by Apr 22, 2024, 3:27 PM

                  @stephenw10 hahah - that could be staged, but it wouldn't be unthinkable that was a legit conversation... I take it that was some video off his doorbell camera or something.

                  Pretty funny either way. But more funny if actually legit conversation.

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                  1 Reply Last reply Reply Quote 0
                  8 out of 8
                  • First post
                    8/8
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                    This community forum collects and processes your personal information.
                    consent.not_received