• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

How can i ban someone from access via mac address ?

Scheduled Pinned Locked Moved Firewalling
5 Posts 4 Posters 3.3k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • C
    cylent
    last edited by Dec 23, 2009, 2:11 PM Dec 23, 2009, 1:58 PM

    I have a list of all DHCP client leases and one of them i dont know who it is. apparently they are plugging in and using the system.

    I have their mac and ip address and would like to block them. how can i achieve this?

    1 Reply Last reply Reply Quote 0
    • S
      shadowadepts
      last edited by Dec 23, 2009, 4:25 PM

      My guess would be assign them a static IP say: 192.168.2.200. then create and alias using host 192.168.2.200 and call it BAN (or something). this way if you see another unwanted you would just have to edit the BAN alias by adding another ip and have to contend with multiple block rules.

      then on your LAN rules at the TOP insert a rule to block all traffic. the rule should look like * BAN * * * *

      gl  8)

      1 Reply Last reply Reply Quote 0
      • C
        cylent
        last edited by Dec 23, 2009, 6:27 PM

        fine. but where do u create this "Alias" you're talking about?

        still sort of new to pfsense

        i am also considering start the captive portal but i fear it may interfere with squid caching …

        1 Reply Last reply Reply Quote 0
        • C
          Cry Havok
          last edited by Dec 23, 2009, 10:03 PM

          Firewall -> Alias

          Also, under Services -> DHCP Server is where you'll want to create the static mapping.

          1 Reply Last reply Reply Quote 0
          • G
            GruensFroeschli
            last edited by Dec 24, 2009, 9:35 AM

            The way you describe it, it sounds like you know every client which has access over the pfSense.
            You could also enable the Captive Portal, put all known MAC addresses on the passthrough list, and all unknown MACs will be displayed the CP.

            Or even more clamped down:
            Create for each client you know a static mapping on the DHCP server page, and then enable static ARP.
            Meaning only the MACs you specified on this page will be able to talk with the pfSense.
            Other MACs wont even get an answer to a DHCP-request.

            We do what we must, because we can.

            Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

            1 Reply Last reply Reply Quote 0
            1 out of 5
            • First post
              1/5
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
              This community forum collects and processes your personal information.
              consent.not_received