LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices

Reply
 
Search this Thread
Old 04-30-2003, 02:19 AM   #1
shahriars
LQ Newbie
 
Registered: Apr 2003
Posts: 22

Rep: Reputation: 15
Question blocking connection through MAC address


Hello! I am wondering if anybody can help me in finding ways to block connection to the server using MAC address. The scenerio is

I have a DHCP server which also acts as a network gateway for my entire LAN. I used to use IP for blocking certain computers to browse the Internet (I have squid running in the same box), but then they would change their IP and get into the Net. I am using RH8.

Now, can anybody please tell me if I can block these connections using MAC address through IPTables, and if yes, how?

If no, what can be an alternative means?

The fact that these connections are using other IP is both annoying and occassionally problematic for me since they are colliding with the eligible IPs as well.

Thanks for your response
 
Old 04-30-2003, 09:12 AM   #2
webtoe
Member
 
Registered: Apr 2001
Location: Cambridge, England
Distribution: Slackware 10, Fedora Core 3, Mac OS X
Posts: 617

Rep: Reputation: 30
Look at the various modules that can be used for iptables. Look in the kernel configuration screen under networking options->ip netfilter configuration->MAC match address support. THat should do the trick.

Actually setting it up is a bit beyond my experience but the documentation should help you.

Alex
 
Old 05-02-2003, 11:00 PM   #3
tyler_durden
Member
 
Registered: May 2001
Posts: 125

Rep: Reputation: 15
You could aslo setup dchp to assign specific IP addresses to specific mac addresses. You could then use regular IP tables to filter out the internet connection
 
Old 05-08-2003, 05:55 AM   #4
Trd79
LQ Newbie
 
Registered: Aug 2001
Location: Sheffield, UK.
Posts: 16

Rep: Reputation: 0
try this

Hi

I think I know what you are trying to do. I would like to so something similar. I would like to force all users to connect using DHCP, and to block users who specify their own IP.

However, if you just want to block certain computers completely, its easy using iptables

iptables -I INPUT -p all -m mac --mac-source aa:bb:cc:dd:ee:ff -j DROP

will prevent connection from the mac address aa:bb:cc:dd:ee:ff

if you want to allow access again just do service firewall restart

To make the changes more permanent (to survive restarting the firewall) you will need to edit rc.firewall

Hope this helps

Let us know if you manage to sort out IP assignments.
 
Old 05-09-2003, 08:13 AM   #5
shahriars
LQ Newbie
 
Registered: Apr 2003
Posts: 22

Original Poster
Rep: Reputation: 15
Talking

yes, it worked :-) I love it ;-)

but as people suspected, I changed -p all to -p tcp, so they can ping, but no internet :-)

thanks thanks and thanks.

all the best
 
Old 06-01-2003, 02:09 PM   #6
daznis
LQ Newbie
 
Registered: Mar 2003
Location: Lithuanina
Distribution: Slackware linux 8.1
Posts: 11

Rep: Reputation: 0
but they can play games cs quake ia
 
Old 06-02-2003, 12:47 AM   #7
shahriars
LQ Newbie
 
Registered: Apr 2003
Posts: 22

Original Poster
Rep: Reputation: 15
well, in my network, they cannot. Any and ALL request to the interface is rejected immediately. Can they play games in yours?
 
Old 06-02-2003, 02:45 PM   #8
daznis
LQ Newbie
 
Registered: Mar 2003
Location: Lithuanina
Distribution: Slackware linux 8.1
Posts: 11

Rep: Reputation: 0
well i have a little home network
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
how to get ip address, broadcast address, mac address of a machine sumeshstar Programming 2 03-12-2005 05:33 AM
blocking mac address and NAT com90185 Linux - Security 6 03-07-2005 07:37 PM
DHCP Server MAC Address found, IP address not assigned wmburke Linux - Wireless Networking 17 11-17-2004 11:33 AM
blocking mac address using iptables Kendo1979 Linux - Networking 9 10-25-2004 05:09 AM
iptables - blocking a host by MAC address retiem Linux - Security 6 08-29-2003 12:58 PM


All times are GMT -5. The time now is 10:43 AM.

Main Menu
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: linuxquestions Google+: linuxquestions
Open Source Consulting | Domain Registration