Networking Forums

Networking Forums > Computer Networking > Linux Networking > iptables mac based filtering

Reply
Thread Tools Display Modes

iptables mac based filtering

 
 
RJ41
Guest
Posts: n/a

 
      09-04-2003, 02:13 PM
Suppose I want to block a Host A which doesnot belong to my subnet and
can change his IP/DNS.

Now I consider blocking host A by its mac address, assuming he doesnot
change his mac address too..

Question is ... that on my subnet, any request coming from host A
would have the mac address of the router connecting my subnet to that
host and not of host A.
So how does mac filter of Iptables would filter out packets coming
from host A based on mac address. Second, How do I determine the mac
address of host A.
 
Reply With Quote
 
 
 
 
Michael Heiming
Guest
Posts: n/a

 
      09-04-2003, 02:25 PM
RJ41 <(E-Mail Removed)> wrote:
....
> from host A based on mac address. Second, How do I determine the mac
> address of host A.


You don't, mac addresses don't transverse subnets, unless using
proxyarp or alike.

--
Michael Heiming

Remove +SIGNS and www. if you expect an answer, sorry for
inconvenience, but I get tons of SPAM
 
Reply With Quote
 
RJ41
Guest
Posts: n/a

 
      09-04-2003, 05:44 PM
Michael Heiming <michael+(E-Mail Removed)> wrote in message news:<(E-Mail Removed)>...
> RJ41 <(E-Mail Removed)> wrote:
> ...
> > from host A based on mac address. Second, How do I determine the mac
> > address of host A.

>
> You don't, mac addresses don't transverse subnets, unless using
> proxyarp or alike.


So that means mac based filtering is applicable only hosts belonging
to the same subnet. proxyarp???
 
Reply With Quote
 
Michael Heiming
Guest
Posts: n/a

 
      09-04-2003, 07:18 PM
RJ41 <(E-Mail Removed)> wrote:
> Michael Heiming <michael+(E-Mail Removed)> wrote in message news:<(E-Mail Removed)>...
> > RJ41 <(E-Mail Removed)> wrote:
> > ...
> > > from host A based on mac address. Second, How do I determine the mac
> > > address of host A.

> >
> > You don't, mac addresses don't transverse subnets, unless using
> > proxyarp or alike.


> So that means mac based filtering is applicable only hosts belonging
> to the same subnet. proxyarp???


Yep, unsure if proxyarp is really what you want, try a google search about
"proxyarp".

--
Michael Heiming

Remove +SIGNS and www. if you expect an answer, sorry for
inconvenience, but I get tons of SPAM
 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
iptables and post-NAT filtering Andrew Gideon Linux Networking 0 07-28-2008 11:50 PM
Do any access points support port-based filtering Peter Broadband 0 10-04-2006 02:00 PM
Filtering rule based on dynamic route dr.minix Linux Networking 1 05-08-2006 04:55 AM
Iptables filtering question George Linux Networking 6 05-20-2005 04:04 PM
looking for new home based router with content filtering abspc Network Routers 0 01-18-2005 07:19 PM



1 2 3 4 5 6 7 8 9 10 11