Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Block iPhones

    Scheduled Pinned Locked Moved Firewalling
    9 Posts 3 Posters 3.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • G
      Gob
      last edited by

      Hi

      It seems that everyone in one of our offices is hooking up their iPhones to the internal WiFi.
      Is there an easy rule to block these connections as you could with the OS fingerprint on desktop computers?

      Cheers
      Gordon

      If I fix one more thing than I break in a day, it's a good day!

      1 Reply Last reply Reply Quote 0
      • B
        blak111
        last edited by

        No, the MAC OS fingerprint doesn't seem to pick them up.
        Why can't you put a wireless key on the access point?

        1 Reply Last reply Reply Quote 0
        • jahonixJ
          jahonix
          last edited by

          From the MAC addresses in your DHCP log you can pick the Apple hosts by their vendor ID.
          My iPhone 3G's MAC starts with: 00:23:df
          and my 3GS MAC begins with: 00:26:08

          Assign them fixed IPs everytime they query DHCP and block those IPs with a rule.
          Changing the MAC in an iPhone isn't as trivial as with other devices.

          Having said this, it is only a workaround.
          Either you have an open WLAN and don't care who does what or you restrict access.

          1 Reply Last reply Reply Quote 0
          • jahonixJ
            jahonix
            last edited by

            Uh, just checked this out.

            Create a block rule on the interface where your iPhones come in. Hit the 'Advanced' button at 'Source port range' and select MacOS as source type OS.
            Maybe this works for iPhoneOS as well.
            Remember that the order of the rules is important.

            Please report back what you find!

            1 Reply Last reply Reply Quote 0
            • G
              Gob
              last edited by

              Thanks for the replies.

              Unfortunately, we also have some legit MACs OSX on that interface.
              I will strip the wireless out onto its own interface and see what I can break after that.

              Cheers
              Gordon

              If I fix one more thing than I break in a day, it's a good day!

              1 Reply Last reply Reply Quote 0
              • B
                blak111
                last edited by

                @jahonix:

                Uh, just checked this out.

                Create a block rule on the interface where your iPhones come in. Hit the 'Advanced' button at 'Source port range' and select MacOS as source type OS.
                Maybe this works for iPhoneOS as well.
                Remember that the order of the rules is important.

                Please report back what you find!

                That's what I was talking about above. I tested that and it didn't pick up the iphone.

                1 Reply Last reply Reply Quote 0
                • jahonixJ
                  jahonix
                  last edited by

                  Well, then I'd say it doesn't work for iPhone OS, just for Mac OS.

                  At least you could create an 'allow Mac OS rule' then…

                  1 Reply Last reply Reply Quote 0
                  • G
                    Gob
                    last edited by

                    now there's lateral thinking!

                    cheers Chris

                    If I fix one more thing than I break in a day, it's a good day!

                    1 Reply Last reply Reply Quote 0
                    • jahonixJ
                      jahonix
                      last edited by

                      @Gob:

                      now there's lateral thinking!

                      Sure. It would get boring otherwise, wouldn't it?  ;-)

                      1. allow MAC OS
                      2. allow Windows
                      3. deny the rest

                      How about that? Rules out iPhones as we just learned.

                      But I'm sure you come up with some VAXes or other uncommon gear and it doesn't work this way. Anyone surfing with a PSP?   ;-)))

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.