From owner-freebsd-questions@FreeBSD.ORG Tue Jun 24 19:23:39 2008 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id E643E1065671 for ; Tue, 24 Jun 2008 19:23:39 +0000 (UTC) (envelope-from chris@smartt.com) Received: from barium.smartt.com (barium.smartt.com [69.67.187.30]) by mx1.freebsd.org (Postfix) with ESMTP id DA3ED8FC0A for ; Tue, 24 Jun 2008 19:23:39 +0000 (UTC) (envelope-from chris@smartt.com) Received: from [69.31.174.220] (unknown [69.31.174.220]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by barium.smartt.com (Postfix) with ESMTPS id DE0D3AC820; Tue, 24 Jun 2008 12:23:38 -0700 (PDT) Message-ID: <486149C4.9050409@smartt.com> Date: Tue, 24 Jun 2008 12:23:48 -0700 From: Chris St Denis User-Agent: Thunderbird 2.0.0.14 (Windows/20080421) MIME-Version: 1.0 To: Yavuz Maslak References: <3d0101c8d61f$65630ea0$dc96eed5@ihlasnetym> In-Reply-To: <3d0101c8d61f$65630ea0$dc96eed5@ihlasnetym> Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit Cc: freebsd-questions@freebsd.org Subject: Re: how to reject all mac addresses except some mac addresses using ipfw? X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 24 Jun 2008 19:23:40 -0000 Yavuz Maslak wrote: > I use ipfw on freebsd7. > > I have two questions > > 1- I want to fix an ip address for each mac address. But some pc and servers have more than an ip address. How can I map multiple ip addresses for a mac address? > 2- I want to allow these fixed mac addresses using ipfw. After that I want to deny all mac address via the server's local ethernet card. How can I do these cases? > > Thanks > > _______________________________________________ > freebsd-questions@freebsd.org mailing list > http://lists.freebsd.org/mailman/listinfo/freebsd-questions > To unsubscribe, send any mail to "freebsd-questions-unsubscribe@freebsd.org" > > I haven't used ipfw for mac level filtering before, but it looks like the syntax is. ipfw add allow MAC any ipfw add allow MAC any ipfw add allow MAC any ipfw add deny MAC any any You'll probably have to include the server's own MAC in that list. -- Chris St Denis Programmer SmarttNet (www.smartt.com) Ph: 604-473-9700 Ext. 200 ------------------------------------------- "Smart Internet Solutions For Businesses"