From owner-freebsd-questions@FreeBSD.ORG Tue Jun 24 18:23:17 2008 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id BE3051065672 for ; Tue, 24 Jun 2008 18:23:17 +0000 (UTC) (envelope-from cswiger@mac.com) Received: from smtpoutm.mac.com (smtpoutm.mac.com [17.148.16.73]) by mx1.freebsd.org (Postfix) with ESMTP id B26938FC16 for ; Tue, 24 Jun 2008 18:23:17 +0000 (UTC) (envelope-from cswiger@mac.com) Received: from asmtp019-bge351000 (asmtp019-bge351000 [10.150.69.82]) by smtpoutm.mac.com (Xserve/smtpout010/MantshX 4.0) with ESMTP id m5OI1kO6016580 for ; Tue, 24 Jun 2008 11:01:46 -0700 (PDT) MIME-version: 1.0 Content-transfer-encoding: 7BIT Content-type: text/plain; charset=US-ASCII; format=flowed; delsp=yes Received: from cswiger1.apple.com ([17.227.140.124]) by asmtp019.mac.com (Sun Java(tm) System Messaging Server 6.3-6.03 (built Mar 14 2008; 32bit)) with ESMTPSA id <0K2Z00EENBEXX400@asmtp019.mac.com> for freebsd-questions@freebsd.org; Tue, 24 Jun 2008 11:01:46 -0700 (PDT) From: Chuck Swiger To: Yavuz Maslak In-reply-to: <3d0101c8d61f$65630ea0$dc96eed5@ihlasnetym> X-Priority: 3 References: <3d0101c8d61f$65630ea0$dc96eed5@ihlasnetym> Message-id: Date: Tue, 24 Jun 2008 11:01:45 -0700 X-Mailer: Apple Mail (2.924) Cc: freebsd-questions@freebsd.org Subject: Re: how to reject all mac addresses except some mac addresses using ipfw? X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 24 Jun 2008 18:23:17 -0000 On Jun 24, 2008, at 10:26 AM, Yavuz Maslak wrote: > 1- I want to fix an ip address for each mac address. But some pc and > servers have more than an ip address. How can I map multiple ip > addresses for a mac address? Most people use ifconfig, perhaps indirectly via /etc/rc.conf. > 2- I want to allow these fixed mac addresses using ipfw. After that > I want to deny all mac address via the server's local ethernet > card. How can I do these cases? Few choose to go that route, but you can disable ARP and set up /etc/ ethers, or you could even fire up your favorite firewall (IPFW, PF, whatever), and add allow rules for the permitted MAC addresses, and deny all others. -- -Chuck