Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Allow Access by MAC only 1

Status
Not open for further replies.

ibredbeard

IS-IT--Management
Jan 5, 2005
26
0
0
GB
Hi,
I searched through this forum and I haven't found a definitive answer to whether you can block access to the internet via MAC addresses. I have a Cisco PIX 506E. Is it possible? Thanks in advance!
 
Since firewalls work on layer-3 and above, there really is no way of filtering via MAC. Layer-2 information is usually just held by the local switch's ARP table, so there is no real way to block it further out.
 
If you have a decent switch attached to the firewall, you could bang on MAC access lists on that switch. They can do MAC address filtering. If this sounds feasible, let me know if you're interested and I can provide the links on how to set it up.
 
There is a way to block by MACs on the Pix, I saw it on a cartoon once but I think it will work in real life. What type of traffic are you looking to block or control rather?
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top