router acl on mac address

router acl on mac address

NewsGroups | Search | Tools

General Cisco Forum - Cisco Systems - Hardware Software and Security News and Discussions 

Page 2 of 2       << first < 1 2 Bookmark this page:  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
router acl on mac address tg 10-09-2008
If you were  Registered and logged in, you could reply and use other advanced thread options
Posted by tg on October 11, 2008, 7:13 pm



> In general, MAC filtering isn't that useful, what are you trying to
> acomplish anyway?

trying to exercise some control over what machines (out there on the
internet) can have access to my mail server on port 25. Filtering based
on ip address is unworkable as people's ip's change all the time. What
doesn't change is their mac address.
I am using multiple barriers against spammers at application level but
if there's anything my router can do to assist in this I want to exploit
that. Someone on the cisco forum told me I could implement mac address
filtering but they didn't elaborate on exactly how it's done.





Posted by Doug McIntyre on October 11, 2008, 11:47 pm


>> In general, MAC filtering isn't that useful, what are you trying to
>> acomplish anyway?

>trying to exercise some control over what machines (out there on the
>internet) can have access to my mail server on port 25. Filtering based
>on ip address is unworkable as people's ip's change all the time. What
>doesn't change is their mac address.
>I am using multiple barriers against spammers at application level but
>if there's anything my router can do to assist in this I want to exploit
>that. Someone on the cisco forum told me I could implement mac address
>filtering but they didn't elaborate on exactly how it's done.


You won't ever see anybody else's MAC address, thats the reason its
not useful. You'll only see your own MAC address, your LAN machines, and
nothing else (assuming your nexthop out is a WAN hop).

Even in a pure LAN environment (ie. a colo data center), you'd only
see the next hop device MAC address and your own.

MAC addresses stay local only to your LAN, by the time the IP packets
get to you, they'll only have your gateway router in them.







Page 2 of 2       << first < 1 2
Similar ThreadsPosted
Blocking a MAC address at the router November 29, 2005, 10:02 am
MAC address for switch and router May 22, 2007, 9:50 pm
LAN IP Address of Router resets on its own May 24, 2007, 1:26 am
web config ip address for an 857 router June 23, 2007, 6:55 am
Newbie-Router Unknown IP address April 4, 2006, 11:39 am
Block MAC-Address on a 2851 Router? December 6, 2007, 1:52 pm
MAC Address and Logical Router Interface November 5, 2008, 5:59 pm
Multicast PIM on Router Loopback with no IP address May 13, 2009, 6:57 am
we have private IP address on WAN port, no connection through Router? October 6, 2005, 4:12 am
Client Gateway Address in DHCP - Router or Firewall? March 1, 2006, 11:00 am

other useful resources:
The Federal Communications Commission (FCC)
Telecommunications Industry Association
Electronic and Software Security Products and Services
International Telecommunication Union

Custom CGI Perl and PHP programming by 1-Script.com

Contact Us | Privacy Policy
The site map in XML format XML site map