Re: blocking MAC address with ipfw ?

2005-05-03 Thread Sandy Rutherford
> On Mon, 02 May 2005 20:26:03 -0700, 
> John Pettitt <[EMAIL PROTECTED]> said:

 > faisal gillani wrote:
 >> faisal gillani wrote:
 >> 
 >> how can i block a MAC address with ipfw ?
 >> can you share the syntax please ?
 >> 
 >> 
 >> thanks
 >> 
 > man ipfw reveals ...

 > { MAC | mac } dst-mac src-mac
 >  Match packets with a given dst-mac and src-mac addresses,
 > speci-
 > ...

You also need to make sure that the sysctl variable
net.link.ether.ipfw is set to 1 to enable layer 2 checks.

Sandy
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Re: blocking MAC address with ipfw ?

2005-05-02 Thread John Pettitt
faisal gillani wrote:

> faisal gillani wrote:
>
>how can i block a MAC address with ipfw ?
>can you share the syntax please ?
>
>
>thanks
>
man ipfw reveals ...

{ MAC | mac } dst-mac src-mac
 Match packets with a given dst-mac and src-mac addresses,
speci-
 fied as the any keyword (matching any MAC address), or six
groups
 of hex digits separated by colons, and optionally followed by a
 mask indicating the significant bits.  The mask may be
specified
 using either of the following methods:

 1.  A slash (/) followed by the number of significant bits.
 For example, an address with 33 significant bits
could be
 specified as:

   MAC 10:20:30:40:50:60/33 any

 2.  An ampersand (&) followed by a bitmask specified as six
 groups of hex digits separated by colons.  For example,
 an address in which the last 16 bits are significant
 could be specified as:

   MAC 10:20:30:40:50:60&00:00:00:00:ff:ff any

 Note that the ampersand character has a special meaning
 in many shells and should generally be escaped.

 Note that the order of MAC addresses (destination first, source
 second) is the same as on the wire, but the opposite of the one
 used for IP addresses.



So

 ipfw add 999 deny MAC any 10:20:30:40:50:60/33

would be a valid rule.

>
>
>*º¤., ¸¸,.¤º*¨¨¨*¤ Allah-hu-Akber*º¤., ¸¸,.¤º*¨¨*¤
>God is the Greatest
>
>
>
>   
>__ 
>Do you Yahoo!? 
>Yahoo! Mail - now with 250MB free storage. Learn more. 
>http://info.mail.yahoo.com/mail_250
>___
>freebsd-questions@freebsd.org mailing list
>http://lists.freebsd.org/mailman/listinfo/freebsd-questions
>To unsubscribe, send any mail to "[EMAIL PROTECTED]"
>
>  
>
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


blocking MAC address with ipfw ?

2005-05-02 Thread faisal gillani
how can i block a MAC address with ipfw ?
can you share the syntax please ?


thanks


*º¤., ¸¸,.¤º*¨¨¨*¤ Allah-hu-Akber*º¤., ¸¸,.¤º*¨¨*¤
God is the Greatest




__ 
Do you Yahoo!? 
Yahoo! Mail - now with 250MB free storage. Learn more. 
http://info.mail.yahoo.com/mail_250
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"