Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    How can i ban someone from access via mac address ?

    Scheduled Pinned Locked Moved Firewalling
    5 Posts 4 Posters 3.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      cylent
      last edited by

      I have a list of all DHCP client leases and one of them i dont know who it is. apparently they are plugging in and using the system.

      I have their mac and ip address and would like to block them. how can i achieve this?

      1 Reply Last reply Reply Quote 0
      • S
        shadowadepts
        last edited by

        My guess would be assign them a static IP say: 192.168.2.200. then create and alias using host 192.168.2.200 and call it BAN (or something). this way if you see another unwanted you would just have to edit the BAN alias by adding another ip and have to contend with multiple block rules.

        then on your LAN rules at the TOP insert a rule to block all traffic. the rule should look like * BAN * * * *

        gl  8)

        1 Reply Last reply Reply Quote 0
        • C
          cylent
          last edited by

          fine. but where do u create this "Alias" you're talking about?

          still sort of new to pfsense

          i am also considering start the captive portal but i fear it may interfere with squid caching …

          1 Reply Last reply Reply Quote 0
          • Cry HavokC
            Cry Havok
            last edited by

            Firewall -> Alias

            Also, under Services -> DHCP Server is where you'll want to create the static mapping.

            1 Reply Last reply Reply Quote 0
            • GruensFroeschliG
              GruensFroeschli
              last edited by

              The way you describe it, it sounds like you know every client which has access over the pfSense.
              You could also enable the Captive Portal, put all known MAC addresses on the passthrough list, and all unknown MACs will be displayed the CP.

              Or even more clamped down:
              Create for each client you know a static mapping on the DHCP server page, and then enable static ARP.
              Meaning only the MACs you specified on this page will be able to talk with the pfSense.
              Other MACs wont even get an answer to a DHCP-request.

              We do what we must, because we can.

              Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.