Old 01-03-2012, 03:13 PM   #1 (permalink)
Master Untangler
 
Join Date: Apr 2008
Location: New Orleans, La
Posts: 103
johndball is on a distinguished road
Default Feature request: MAC filtering/blocking

If there isn't a way to do this now, could there be an option to allow for the filtering, or blocking, of MAC addresses?
johndball is offline  
Old 01-03-2012, 03:51 PM   #2 (permalink)
Master Untangler
 
f1assistance's Avatar
 
Join Date: Apr 2009
Location: Holly Springs, NC
URLs submitted: 154
Posts: 218
f1assistance is on a distinguished road
Default

Quote:
Originally Posted by johndball View Post
If there isn't a way to do this now, could there be an option to allow for the filtering, or blocking, of MAC addresses?
Depending on your LAN configuration, you might assign a static IP Address to the MAC Address (DHCP Server) then block that IP Address external access...
__________________
Untangle...because nothing is worse than doing nothing!
-------
2, Pentium (R) Dual-Core CPU E5300 @ 2.60GHz 2599.968, 2089.96MB RAM
f1assistance is offline  
Old 01-03-2012, 03:57 PM   #3 (permalink)
Master Untangler
 
Join Date: Apr 2008
Location: New Orleans, La
Posts: 103
johndball is on a distinguished road
Default

I can/have/would do this but it is far too easy for somebody to change the IP address of the computer and get around any blocks.*

Here is the setup I have, and it works well, but I'd like to lock it down even further.

The fist layer we have is HP ProCurve switches with port filtering based on MAC addresses. If somebody plugs into a port and that MAC address is not in the allow list for that port the port shuts down.

Secondly, we have Windows Firewall running on the domain to block ALL traffic to and from ANY IP address that is not on the allow list. The IP addresses on the allow list are those workstations and network equipment that is authorized to be on the network.

I'd like to add an extra layer using the Untangle Firewall. If somebody accesses the network and bypasses our servers or doesn't require the services of our servers (DHCP and DNS) but sends traffic directly to the firewall I'd like for the firewall to drop/block the traffic.

*This isn't on domain-owned workstations (which are locked down) but on laptops or mobile hard-wired devices that somebody might bring into the facility. I'm only thinking about this now because we had a breach last night. A combination of safeguards weren't enabled due to the failure of multiple individuals and a breach occurred. Granted access, to my knowledge, wasn't obtained thanks to the switch security policies but it would be nice to have an additional layer on the firewall.

Last edited by johndball; 01-03-2012 at 04:00 PM..
johndball is offline  
Old 01-03-2012, 04:06 PM   #4 (permalink)
Master Untangler
 
f1assistance's Avatar
 
Join Date: Apr 2009
Location: Holly Springs, NC
URLs submitted: 154
Posts: 218
f1assistance is on a distinguished road
Default

Captive Portal
__________________
Untangle...because nothing is worse than doing nothing!
-------
2, Pentium (R) Dual-Core CPU E5300 @ 2.60GHz 2599.968, 2089.96MB RAM
f1assistance is offline  
Old 01-04-2012, 04:19 AM   #5 (permalink)
Untangle Ninja
 
dwasserman's Avatar
 
Join Date: Jun 2008
Location: Argentina
URLs submitted: 57
Posts: 3,634
dwasserman is on a distinguished road
Default

In Config/Networking/Advanced/PacketFilter you have the Source Mac Address option

packetfiltermac.JPG
__________________
The world is divided into 10 kinds of people, who know binary and those not
dwasserman is offline  
Old 01-04-2012, 10:24 AM   #6 (permalink)
Untangle Ninja
 
YeOldeStonecat's Avatar
 
Join Date: Aug 2007
Posts: 1,391
YeOldeStonecat is on a distinguished road
Default

Quote:
Originally Posted by johndball View Post
I can/have/would do this but it is far too easy for somebody to change the IP address of the computer and get around any blocks.*
To be honest....if someone is savvy enough to do the above, they are savvy enough to run a MAC spoofing software on their PC too.

Control them via DHCP reservation, IP address...and don't give them local admin rights to change their network settings.
YeOldeStonecat is online now  
Old 01-04-2012, 10:33 AM   #7 (permalink)
Untangle Ninja
 
sky-knight's Avatar
 
Join Date: Apr 2008
Location: Phoenix, AZ
URLs submitted: 8
Posts: 15,454
sky-knight is on a distinguished road
Default

That doesn't need special software. For windows it's a property of the NIC in device manager, and for Linux/Mac is an ifconfig line on the command line. MAC controls are not more secure than IP level controls. If you require this level of control of your network, please look into NAC enabled switches.

Also, Untangle has MAC address controls, they are in the packet filter.
__________________
Rob Sandling, BS:SWE, MCP
Intouch Technology
Phone: 480-272-9889
rob@intouchtechllc.com

UntangleAppliances.com
Phone: 866-794-8879
sky-knight is offline  
Old 01-05-2012, 12:16 PM   #8 (permalink)
Master Untangler
 
Join Date: Apr 2008
Location: New Orleans, La
Posts: 103
johndball is on a distinguished road
Default

Quote:
Originally Posted by dwasserman View Post
In Config/Networking/Advanced/PacketFilter you have the Source Mac Address option

Attachment 4375
Just what I was needed. Thanks!
johndball is offline  
Old 01-05-2012, 03:53 PM   #9 (permalink)
Untangle Ninja
 
Mathiau's Avatar
 
Join Date: Feb 2008
Location: Costa Frickn' Rica
Posts: 1,467
Mathiau is on a distinguished road
Send a message via AIM to Mathiau Send a message via MSN to Mathiau Send a message via Yahoo to Mathiau
Default

Quote:
Originally Posted by YeOldeStonecat View Post
To be honest....if someone is savvy enough to do the above, they are savvy enough to run a MAC spoofing software on their PC too.

Control them via DHCP reservation, IP address...and don't give them local admin rights to change their network settings.
Bingo, you need to implement proper system level security.
__________________
Def1:Started:UT 7.1 x64 -- Current :UT 9.1 x64| Gigabyte GM-G31 mATX | Intel Q8200 | 8G DDR2 800 | 80G WD | 4x Intel Pro 1000 GT NIC's | Corsair 550W PSU | Norco RPC-250 2U Case | 50mb/50mb | 10 users
Mathiau is offline  
Old 01-05-2012, 03:55 PM   #10 (permalink)
Master Untangler
 
Join Date: Apr 2008
Location: New Orleans, La
Posts: 103
johndball is on a distinguished road
Default

It's already implemented. Read my second post on this thread.

This request was for an additional layer, not primary.
johndball is offline  
Closed Thread

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 05:55 AM.


© 2010 Untangle, Inc. All Rights Reserved.   SEO by vBSEO 3.6.0 PL2