MAC locking and filtering in FreeBSD

Brett Glass brett at lariat.net
Wed May 13 17:18:15 UTC 2009


I need to find a way to do "MAC address locking" in FreeBSD -- that 
is, to ensure that only a machine with a particular MAC address can 
use a particular IP address. Unfortunately, it appears that rules 
in FreeBSD's IPFW are "stuck" on one layer: rules that look at 
Layer 2 information in a packet can't look at Layer 3, and vice 
versa. Is there a way to work around this to do MAC address locking 
and/or other functions that involve looking at Layer 2 and Layer 3 
simultaneously?

--Brett Glass



More information about the freebsd-net mailing list