From owner-freebsd-questions@FreeBSD.ORG Mon Jun 11 22:18:25 2012 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 47B9C106566B for ; Mon, 11 Jun 2012 22:18:25 +0000 (UTC) (envelope-from merlyn@stonehenge.com) Received: from gw17.lax01.mailroute.net (lax-gw17.mailroute.net [199.89.0.117]) by mx1.freebsd.org (Postfix) with ESMTP id 225F68FC08 for ; Mon, 11 Jun 2012 22:18:25 +0000 (UTC) Received: from localhost (localhost.localdomain [127.0.0.1]) by gw17.lax01.mailroute.net (Postfix) with ESMTP id A2964666367; Mon, 11 Jun 2012 22:18:19 +0000 (GMT) X-Virus-Scanned: by MailRoute Received: from gw17.lax01.mailroute.net ([199.89.0.117]) by localhost (gw17.lax01.mailroute.net.mailroute.net [127.0.0.1]) (mroute_mailscanner, port 10026) with LMTP id xb7U_FSST4Yn; Mon, 11 Jun 2012 22:18:18 +0000 (GMT) Received: from red.stonehenge.com (red.stonehenge.com [208.79.95.2]) by gw17.lax01.mailroute.net (Postfix) with ESMTP id 7962E666392; Mon, 11 Jun 2012 22:18:18 +0000 (GMT) Received: by red.stonehenge.com (Postfix, from userid 1001) id 5D69E12CA; Mon, 11 Jun 2012 15:18:18 -0700 (PDT) From: merlyn@stonehenge.com (Randal L. Schwartz) To: Bill Yuan References: <20120610120041.4D0F610657C3@hub.freebsd.org> <20120611025332.N46641@sola.nimnet.asn.au> x-mayan-date: Long count = 12.19.19.8.7; tzolkin = 6 Manik; haab = 10 Zotz Date: Mon, 11 Jun 2012 15:18:18 -0700 In-Reply-To: (Bill Yuan's message of "Mon, 11 Jun 2012 11:39:56 +0800") Message-ID: <863961ze51.fsf@red.stonehenge.com> User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/23.4 (berkeley-unix) MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Cc: Ian Smith , "Brian W." , freebsd-questions@freebsd.org Subject: Re: how to allow by MAC X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 11 Jun 2012 22:18:25 -0000 >>>>> "Bill" == Bill Yuan writes: Bill> I want to create a white list MAC address, Only the machine which it's MAC Bill> in the white list will be allowed, all others will be blocked. Bad idea. Since (a) every MAC address that *is* allowed is transmitted in the clear and (b) it's trivial to spoof a MAC address. This. is. no. security. Please stop even trying. -- Randal L. Schwartz - Stonehenge Consulting Services, Inc. - +1 503 777 0095 Smalltalk/Perl/Unix consulting, Technical writing, Comedy, etc. etc. See http://methodsandmessages.posterous.com/ for Smalltalk discussion