Do you recognize a good idea when you see one? We want to hear from you!
Header Image

I suggest you ...

Network Security: MAC-Based Packet Filter Rules

Provide a means whereby the MAC addresses of hardware can be used to craft packet filter rules.. Provides more precise security by avoiding the ability for a user to force an IP which should not be theirs, and thus gain access to filters based on that IP.

519 votes
Vote
Sign in
Check!
(thinking…)
Reset
or sign in with
  • facebook
  • google
    Password icon
    I agree to the terms of service
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    Gert HansenGert Hansen shared this idea  ·   ·  Flag idea as inappropriate…  ·  Admin →
    Andre BougherAndre Bougher shared a merged idea: Allow Firewall Filtering by MAC Address  ·   · 
    Pascal BarufkePascal Barufke shared a merged idea: MAC based Host definitons, if possible with wildcards for vendor specific packet filter rules  ·   · 

    46 comments

    Sign in
    Check!
    (thinking…)
    Reset
    or sign in with
    • facebook
    • google
      Password icon
      I agree to the terms of service
      Signed in as (Sign out)
      Submitting...
      • Rhapsody BarbrowRhapsody Barbrow commented  ·   ·  Flag as inappropriate

        looks like "late" 2012 isn't going to happen.....what about 2013 q1 is that still on the table?

      • Casey CCasey C commented  ·   ·  Flag as inappropriate

        Please add this feature. It is crucial for our RED deployments to have the ability to lock down which devices can connect from behind them.

      • AnonymousAnonymous commented  ·   ·  Flag as inappropriate

        PLEASE - This is a basic feature other firewalls have and is extremely useful when users are changing IP address to bypass security

      • Ahmad ChughtaiAhmad Chughtai commented  ·   ·  Flag as inappropriate

        We would definitely like to have this feature. We need to restrict our remote users to certain devices that they use to access our system. It is becoming critical for us.

        Ahmad Chughtai
        Opus Capital Markets, IL

      • Leland VandervortLeland Vandervort commented  ·   ·  Flag as inappropriate

        A definite requirement when using REDs in bridged LAN mode. The ability to apply MAC-based packet filter rules will also help avoid remote-site users from trying to connect any old device onto the corporate network from behind the RED/bridge.

      • me.yahoo.com/a/qltx3fo3n_b3x26stw79i7bbnzkiwzdgme.yahoo.com/a/qltx3fo3n_b3x26stw79i7bbnzkiwzdg commented  ·   ·  Flag as inappropriate

        PLEASE incorporate this functionality soon. I have certain abusers that are able to somehow circumvent our P2P restrictions and due to the kind of company we are, where employees bring in their personal equipment, IP filtering is not an answer.

      • BillBill commented  ·   ·  Flag as inappropriate

        Very frustrating that I cannot do this! I've got a client who has plugged an unauthorized device into the network and I'd like to restrict it's access.

      • CJLCJL commented  ·   ·  Flag as inappropriate

        Perhaps since Astaro is a security company, they hesitate to implement something as inherently insecure as MAC address filtering.

      • fritz jungfritz jung commented  ·   ·  Flag as inappropriate

        This feature as a basic function of good firewall systems. I looked for this feature in the documentation, but haven't found it. I wish that the astaro developers implement this feature ASAP.

      • Scott KlassenScott Klassen commented  ·   ·  Flag as inappropriate

        The status is that it is a feature request with a lot of points. If Astaro is actively considering adding this feature the status will change to "under review". If Astaro decides to add it, the status will change to "planned". If coding work has begun, the status will change to "started".

      • fmurdicafmurdica commented  ·   ·  Flag as inappropriate

        Really would like to see this feature, like other have said cheap linksys routers can do it, why cant astaro do it.

      • bgarlockbgarlock commented  ·   ·  Flag as inappropriate

        I really thought I was overlooking this feature, and didn't realize it wasn't possible. Even the cheapest Linksys firewalls can easily do this.

        This is Linux, so just about anythings possible - I hope this feature comes out soon!

      ← Previous 1 3

      Feedback and Knowledge Base