<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[7100 : spoof MAC ?]]></title><description><![CDATA[<p dir="auto">Yes, I searched via Search function:<br />
Is it possible to spoof the underlying MAC of an interface on a Netgate 7100?</p>
<p dir="auto">I have a cold standby appliance that should act and look like another Netgate 7100.<br />
One of the WAN-providers filters for that MAC ... and WAN doesn't come online without that.</p>
<p dir="auto">As the WAN etc already is configured as VLAN etc (factory config) it can't be easily done in the interface section of pfSense.</p>
<p dir="auto">I assume I have to touch the switch configuration?</p>
<p dir="auto">I think I did that once some years ago, any definitive HOWTO would make this easier, thanks!</p>
]]></description><link>https://forum.netgate.com/topic/200699/7100-spoof-mac</link><generator>RSS for Node</generator><lastBuildDate>Sat, 13 Jun 2026 00:31:44 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/200699.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 18 May 2026 10:32:45 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to 7100 : spoof MAC ? on Fri, 05 Jun 2026 10:49:12 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/stephenw10">@<bdi>stephenw10</bdi></a> said in <a href="/post/1243696">7100 : spoof MAC ?</a>:</p>
<blockquote>
<p dir="auto">Nice. Good result! <img src="https://forum.netgate.com/assets/plugins/nodebb-plugin-emoji/emoji/android/1f44d.png?v=717669fab53" class="not-responsive emoji emoji-android emoji--+1" style="height:23px;width:auto;vertical-align:middle" title=":+1:" alt="👍" /></p>
</blockquote>
<p dir="auto">It's an honor to hear this from you, thanks ;-)</p>
]]></description><link>https://forum.netgate.com/post/1243698</link><guid isPermaLink="true">https://forum.netgate.com/post/1243698</guid><dc:creator><![CDATA[sgw]]></dc:creator><pubDate>Fri, 05 Jun 2026 10:49:12 GMT</pubDate></item><item><title><![CDATA[Reply to 7100 : spoof MAC ? on Fri, 05 Jun 2026 10:22:07 GMT]]></title><description><![CDATA[<p dir="auto">Nice. Good result! <img src="https://forum.netgate.com/assets/plugins/nodebb-plugin-emoji/emoji/android/1f44d.png?v=717669fab53" class="not-responsive emoji emoji-android emoji--+1" style="height:23px;width:auto;vertical-align:middle" title=":+1:" alt="👍" /></p>
]]></description><link>https://forum.netgate.com/post/1243696</link><guid isPermaLink="true">https://forum.netgate.com/post/1243696</guid><dc:creator><![CDATA[stephenw10]]></dc:creator><pubDate>Fri, 05 Jun 2026 10:22:07 GMT</pubDate></item><item><title><![CDATA[Reply to 7100 : spoof MAC ? on Fri, 05 Jun 2026 09:28:39 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/stephenw10">@<bdi>stephenw10</bdi></a></p>
<p dir="auto">Yes, the internal switch config on Appliance was missing the configs for the additional WAN-interfaces.</p>
<p dir="auto">The MAC-spoofing might not be needed at all, a test with a random laptop came online on that upstream fiber gateway without problems (with some random MAC).</p>
<p dir="auto">Now with the correct VLANs etc on the internal switch the plugging works perfectly (we can plug between the 2 appliances and connectivity is up immediately).</p>
<p dir="auto">thanks!</p>
]]></description><link>https://forum.netgate.com/post/1243690</link><guid isPermaLink="true">https://forum.netgate.com/post/1243690</guid><dc:creator><![CDATA[sgw]]></dc:creator><pubDate>Fri, 05 Jun 2026 09:28:39 GMT</pubDate></item><item><title><![CDATA[Reply to 7100 : spoof MAC ? on Wed, 03 Jun 2026 19:23:12 GMT]]></title><description><![CDATA[<p dir="auto">What might be happening is the switch config is different. That doesn't get synced so it's possible you have the VLAN assigned to a different port on the secondary node. It's unlikely though if you restored a config onto the secondary from the primary when creating it.<br />
But it's easy enough to compare the switch config on each node.</p>
]]></description><link>https://forum.netgate.com/post/1243637</link><guid isPermaLink="true">https://forum.netgate.com/post/1243637</guid><dc:creator><![CDATA[stephenw10]]></dc:creator><pubDate>Wed, 03 Jun 2026 19:23:12 GMT</pubDate></item><item><title><![CDATA[Reply to 7100 : spoof MAC ? on Wed, 03 Jun 2026 19:15:39 GMT]]></title><description><![CDATA[<p dir="auto">I have a theory ... we might test that on friday or tuesday.</p>
<p dir="auto">Maybe on appliance 2 the assigned order of the interfaces got mixed up?</p>
<p dir="auto">I am not 100% sure if that is possible, the config.xml was restored so that should be identical.</p>
<p dir="auto">What I think of: the local admin plugs the cable for WAN2 into ETH2 on App1 and things work (I just make up an example).</p>
<p dir="auto">So we'd assume ETH2 on Appliance2 should also be assigned to WAN2 (and use its configured static IP etc). The admin just plugs the cable FROM App1:ETH2 TO App2:ETH2 ...</p>
<p dir="auto">If that's not the case and for some reason WAN2 points to ETH3 on Appliance2 (because of whatever ... timings at bootup?) this would result in the logged behavior: ETH2 plugged in would show the spoofed MAC, but no configured IP.</p>
<p dir="auto">The theory maybe lacks a bit .. but could that be the case?</p>
]]></description><link>https://forum.netgate.com/post/1243616</link><guid isPermaLink="true">https://forum.netgate.com/post/1243616</guid><dc:creator><![CDATA[sgw]]></dc:creator><pubDate>Wed, 03 Jun 2026 19:15:39 GMT</pubDate></item><item><title><![CDATA[Reply to 7100 : spoof MAC ? on Wed, 20 May 2026 12:32:25 GMT]]></title><description><![CDATA[<p dir="auto">Really the only significant difference would be the overhead the tagging adds meaning the path MTU might be slightly lower. But that would be identical between the two 7100s. And it wouldn't prevent connecting entirely.</p>
]]></description><link>https://forum.netgate.com/post/1242921</link><guid isPermaLink="true">https://forum.netgate.com/post/1242921</guid><dc:creator><![CDATA[stephenw10]]></dc:creator><pubDate>Wed, 20 May 2026 12:32:25 GMT</pubDate></item><item><title><![CDATA[Reply to 7100 : spoof MAC ? on Wed, 20 May 2026 11:39:10 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/stephenw10">@<bdi>stephenw10</bdi></a> thank you. Even more of a mystery.<br />
I am curious what the upstream support replies.<br />
I don't expect much ...</p>
]]></description><link>https://forum.netgate.com/post/1242916</link><guid isPermaLink="true">https://forum.netgate.com/post/1242916</guid><dc:creator><![CDATA[sgw]]></dc:creator><pubDate>Wed, 20 May 2026 11:39:10 GMT</pubDate></item><item><title><![CDATA[Reply to 7100 : spoof MAC ? on Wed, 20 May 2026 10:38:05 GMT]]></title><description><![CDATA[<p dir="auto">Yes the internal switch. The upstream devices shouldn't see any of the LAGG or VLAN specific packets.</p>
]]></description><link>https://forum.netgate.com/post/1242902</link><guid isPermaLink="true">https://forum.netgate.com/post/1242902</guid><dc:creator><![CDATA[stephenw10]]></dc:creator><pubDate>Wed, 20 May 2026 10:38:05 GMT</pubDate></item><item><title><![CDATA[Reply to 7100 : spoof MAC ? on Wed, 20 May 2026 05:15:36 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/stephenw10">@<bdi>stephenw10</bdi></a></p>
<p dir="auto">You talk of the internal switch?<br />
There is no switch between the 7100 and the fiber-appliance.</p>
<p dir="auto">Thanks for clarifying. It was just a wild guess while I was listing the possible differences between plugging in the 2 7100-appliances.</p>
]]></description><link>https://forum.netgate.com/post/1242882</link><guid isPermaLink="true">https://forum.netgate.com/post/1242882</guid><dc:creator><![CDATA[sgw]]></dc:creator><pubDate>Wed, 20 May 2026 05:15:36 GMT</pubDate></item><item><title><![CDATA[Reply to 7100 : spoof MAC ? on Tue, 19 May 2026 20:02:43 GMT]]></title><description><![CDATA[<p dir="auto">The spoofed MAC definitely shows up for me. The upstream router shows it in its ARP table or a pcap.</p>
<p dir="auto">The LAGG and VLAN shouldn't make any difference. None of that layer 2 stuff exists beyond the switch.</p>
]]></description><link>https://forum.netgate.com/post/1242874</link><guid isPermaLink="true">https://forum.netgate.com/post/1242874</guid><dc:creator><![CDATA[stephenw10]]></dc:creator><pubDate>Tue, 19 May 2026 20:02:43 GMT</pubDate></item><item><title><![CDATA[Reply to 7100 : spoof MAC ? on Tue, 19 May 2026 17:55:06 GMT]]></title><description><![CDATA[<p dir="auto">Hmm.<br />
The spoofing worked. I assigned etc then we had to powercycle the box to get it online again.</p>
<p dir="auto">After that the displayed MAC was the spoofed one. Looked OK.</p>
<p dir="auto">BUT the fiber-router (or whatever that is) didn't "see" the pfSense interface connected.<br />
We had the admin of the provider on the phone, he ran diagnostics, we rebooted and replugged that router without getting it online.</p>
<p dir="auto">We had electrical link, but he didn't see the MAC arp-wise (I assume).</p>
<p dir="auto">Plugging back to the original appliance (without spoofing) worked immediately.</p>
<p dir="auto">The provider-admin asks upstream .. he is only the tech for the reseller, or so.</p>
<p dir="auto">I wonder: could the fact that it's a LAGG be a problem? I think of stuff like LACP, STP or whatever is different from a plain access interface.</p>
<p dir="auto">I am just wondering what's the difference from the view of that fiber-box.</p>
<p dir="auto">I'll keep you posted. Maybe I hear something tomorrow.</p>
]]></description><link>https://forum.netgate.com/post/1242870</link><guid isPermaLink="true">https://forum.netgate.com/post/1242870</guid><dc:creator><![CDATA[sgw]]></dc:creator><pubDate>Tue, 19 May 2026 17:55:06 GMT</pubDate></item><item><title><![CDATA[Reply to 7100 : spoof MAC ? on Tue, 19 May 2026 15:45:32 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/stephenw10">@<bdi>stephenw10</bdi></a> great, thanks.<br />
We maybe try that in about 1.5 hours from now.</p>
]]></description><link>https://forum.netgate.com/post/1242867</link><guid isPermaLink="true">https://forum.netgate.com/post/1242867</guid><dc:creator><![CDATA[sgw]]></dc:creator><pubDate>Tue, 19 May 2026 15:45:32 GMT</pubDate></item><item><title><![CDATA[Reply to 7100 : spoof MAC ? on Tue, 19 May 2026 14:04:48 GMT]]></title><description><![CDATA[<p dir="auto">Yes exactly, you need to assign lagg0 as an interface so you can set it's properties in the gui. Then enable the assigned interface and set the MAC there. No need to set anything else on the interface.</p>
<p dir="auto"><img src="/assets/uploads/files/1779199471107-screenshot-from-2026-05-19-15-04-10.png" alt="Screenshot from 2026-05-19 15-04-10.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/post/1242862</link><guid isPermaLink="true">https://forum.netgate.com/post/1242862</guid><dc:creator><![CDATA[stephenw10]]></dc:creator><pubDate>Tue, 19 May 2026 14:04:48 GMT</pubDate></item><item><title><![CDATA[Reply to 7100 : spoof MAC ? on Tue, 19 May 2026 13:59:15 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/stephenw10">@<bdi>stephenw10</bdi></a> said in <a href="/post/1242838">7100 : spoof MAC ?</a>:</p>
<blockquote>
<p dir="auto">Hmm, so there is no LAGG interface on the standby device?</p>
</blockquote>
<p dir="auto">That one is offline right now. It's the same config as the online device -&gt;</p>
<blockquote>
<p dir="auto">lagg0 is in the default config for the 7100. It can be removed to create other configs, multiple WAN MACs for example.<br />
It is not assigned as an interface by default though and you need to do that to get the MAC spoof field.</p>
<p dir="auto">But, yes, adding or removing that means re-configuring the switch and it's <em>VERY</em> easy to loose connectivity if that's how you are connected.</p>
</blockquote>
<p dir="auto">It is visible as "Available network port", but not yet assigned on the active device (in <code>interfaces_assign.php</code>).</p>
<p dir="auto">I won't try that now, I could try it on the 2nd device in a maintenance window (plus the spoofing part).</p>
<p dir="auto">I wouldn't remove the Interface LAGG0, I would only add an "Interface Assignment" to then be able to spoof the MAC there. Right?</p>
<p dir="auto">I think I know my way, I have to make that appointment with the local admin guy first.</p>
<p dir="auto">thanks</p>
]]></description><link>https://forum.netgate.com/post/1242860</link><guid isPermaLink="true">https://forum.netgate.com/post/1242860</guid><dc:creator><![CDATA[sgw]]></dc:creator><pubDate>Tue, 19 May 2026 13:59:15 GMT</pubDate></item><item><title><![CDATA[Reply to 7100 : spoof MAC ? on Tue, 19 May 2026 09:54:58 GMT]]></title><description><![CDATA[<p dir="auto">Hmm, so there is no LAGG interface on the standby device?</p>
<p dir="auto">lagg0 is in the default config for the 7100. It can be removed to create other configs, multiple WAN MACs for example.<br />
It is not assigned as an interface by default though and you need to do that to get the MAC spoof field.</p>
<p dir="auto">But, yes, adding or removing that means re-configuring the switch and it's <em>VERY</em> easy to loose connectivity if that's how you are connected.</p>
]]></description><link>https://forum.netgate.com/post/1242838</link><guid isPermaLink="true">https://forum.netgate.com/post/1242838</guid><dc:creator><![CDATA[stephenw10]]></dc:creator><pubDate>Tue, 19 May 2026 09:54:58 GMT</pubDate></item><item><title><![CDATA[Reply to 7100 : spoof MAC ? on Tue, 19 May 2026 04:47:19 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/stephenw10">@<bdi>stephenw10</bdi></a> Ah, I see.<br />
On the first appliance (which runs right now) I can see there is that LAGG0 already.<br />
As I haven't created it myself it was also already rebooted ;-)</p>
<p dir="auto">But there is no field for assigning a MAC in the GUI.</p>
<p dir="auto">Recreating sounds dangerous: wouldn't I lose connectivity then? I very likely have to do that from remote, so I'd need a safe procedure.</p>
<p dir="auto">Bonus question: the resulting config would also work unchanged on the appliance with "physical MAC = spoofed MAC" ?</p>
<p dir="auto">thanks!</p>
]]></description><link>https://forum.netgate.com/post/1242822</link><guid isPermaLink="true">https://forum.netgate.com/post/1242822</guid><dc:creator><![CDATA[sgw]]></dc:creator><pubDate>Tue, 19 May 2026 04:47:19 GMT</pubDate></item><item><title><![CDATA[Reply to 7100 : spoof MAC ? on Mon, 18 May 2026 15:51:35 GMT]]></title><description><![CDATA[<p dir="auto">The MAC can be spoofed in the default config by assigning and enabling LAGG0 which is the parent for the WAN and LAN VLANs. You can then spoof the MAC on the LAGG and the VLANs will inherit that:</p>
<pre><code>lagg0: flags=1008943&lt;UP,BROADCAST,RUNNING,PROMISC,SIMPLEX,MULTICAST,LOWER_UP&gt; metric 0 mtu 1500
	description: OPT4
	options=4e138bb&lt;RXCSUM,TXCSUM,VLAN_MTU,VLAN_HWTAGGING,JUMBO_MTU,VLAN_HWCSUM,WOL_UCAST,WOL_MCAST,WOL_MAGIC,VLAN_HWFILTER,RXCSUM_IPV6,TXCSUM_IPV6,HWSTATS,MEXTPG&gt;
	ether 00:11:22:33:44:55
	hwaddr 00:00:00:00:00:00
	inet6 fe80::208:a2ff:fe0e:a593%lagg0 prefixlen 64 scopeid 0x17
	laggproto loadbalance lagghash l2,l3,l4
	laggport: ix2 flags=4&lt;ACTIVE&gt;
	laggport: ix3 flags=4&lt;ACTIVE&gt;
	groups: lagg
	media: Ethernet autoselect
	status: active
	nd6 options=21&lt;PERFORMNUD,AUTO_LINKLOCAL&gt;
lagg0.4091: flags=1008843&lt;UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST,LOWER_UP&gt; metric 0 mtu 1500
	options=4600003&lt;RXCSUM,TXCSUM,RXCSUM_IPV6,TXCSUM_IPV6,MEXTPG&gt;
	ether 00:11:22:33:44:55
	inet 192.168.127.1 netmask 0xffffff00 broadcast 192.168.127.255
	inet6 fe80::211:22ff:fe33:4455%lagg0.4091 prefixlen 64 scopeid 0x18
	groups: vlan
	vlan: 4091 vlanproto: 802.1q vlanpcp: 0 parent interface: lagg0
	media: Ethernet autoselect
	status: active
	nd6 options=21&lt;PERFORMNUD,AUTO_LINKLOCAL&gt;
lagg0.4090: flags=1008943&lt;UP,BROADCAST,RUNNING,PROMISC,SIMPLEX,MULTICAST,LOWER_UP&gt; metric 0 mtu 1500
	options=4000000&lt;MEXTPG&gt;
	ether 00:11:22:33:44:55
	inet 172.21.16.219 netmask 0xffffff00 broadcast 172.21.16.255
	inet6 fe80::211:22ff:fe33:4455%lagg0.4090 prefixlen 64 scopeid 0x19
	groups: vlan
	vlan: 4090 vlanproto: 802.1q vlanpcp: 0 parent interface: lagg0
	media: Ethernet autoselect
	status: active
	nd6 options=23&lt;PERFORMNUD,ACCEPT_RTADV,AUTO_LINKLOCAL&gt;
</code></pre>
<p dir="auto">You will need to reboot or recreate the LAGG to see that change.</p>
<p dir="auto">So no need to do anything with the switch if that is sufficient.</p>
]]></description><link>https://forum.netgate.com/post/1242807</link><guid isPermaLink="true">https://forum.netgate.com/post/1242807</guid><dc:creator><![CDATA[stephenw10]]></dc:creator><pubDate>Mon, 18 May 2026 15:51:35 GMT</pubDate></item></channel></rss>