Re: Allowing access to IP/MAC pairs only



On Thu, Jan 31, 2008 at 10:30:53AM -0800, Szemer?dy G?bor wrote:

We have feeBSD 6.2 machines with local subnets on the servers and would
like to allow access to the internet only for workstations with exact
IP/MAC pairs and deny access for not predefined pairs.
Is there a solution in firewall settings?

You need not any firewall for that.
Just use "ifconfig em0 staticarp" disable ARP table updates
for interface em0 (replace em0 with your interface name)
and load IP/MAC pairs into ARP table with "arp -f arps_em0" command
where file named "arps_em0" contains those pairs:

10.10.10.10 00:11:22:33:44:55
10.10.10.11 00:11:22:33:44:56
10.10.10.12 00:11:22:33:44:57

Eugene Grosbein
_______________________________________________
freebsd-stable@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-stable
To unsubscribe, send any mail to "freebsd-stable-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • Re: Newbie Question; security logs
    ... I think IP firewall is blocking all unauthorized ... The Handbook's "Security" chapter is required reading, ... Use good passwords. ... use /etc/hosts.allow, and deny access ...
    (freebsd-newbies)
  • Re: Most Popular Hardware Firewalls?
    ... but a properly setup firewall is ... want to deny access to Google? ... Blockeing PARTICULAR javascript exploits, etc. ... I wouldn't even call it blocking, ...
    (comp.security.firewalls)
  • RE: windows blocked internet access to yahoo IM
    ... Are you sure you do not have a different Firewall to vista's firewall? ... When I was trying to shut off the computer, I got the message "yahoo IM is ... trying to connect to your computer allow or deny access". ... I've tried to search through the security info but I can't seem to access ...
    (microsoft.public.windows.vista.security)
  • MVFATC
    ... I will deny access through the ... be something esle spawning it. ... >My firewall has a frequent request from mvfatc.exe for ... >anywhere in the MS KB or in a general Internet search. ...
    (microsoft.public.security)