Limit MAC Addresses

DOWNLOAD THE LATEST FIRMWARE HERE
User avatar
mhoppes
Associate
Associate
 
Posts: 664
Joined: Thu Apr 10, 2014 9:14 pm
Location: Pennsylvania
Has thanked: 10 times
Been thanked: 125 times

Limit MAC Addresses

Mon Apr 20, 2015 12:47 pm

I know we can limit speeds by port.... is it possible to limit the number of MAC addresses associated with one port (say if I'm handing a port off to a customer and I want to prohibit them from connecting more than X devices?)

User avatar
adairw
Associate
Associate
 
Posts: 465
Joined: Wed Nov 05, 2014 11:47 pm
Location: Amarillo, TX
Has thanked: 98 times
Been thanked: 132 times

Re: Limit MAC Addresses

Tue Apr 21, 2015 11:19 am

This would be a sweet feature and seems like it wouldn't be hard to code in if the switch chip supports it.

User avatar
wayneorack
Experienced Member
 
Posts: 129
Joined: Thu Sep 04, 2014 12:16 pm
Location: San Angelo, TX
Has thanked: 188 times
Been thanked: 64 times

Re: Limit MAC Addresses

Tue Apr 21, 2015 11:58 am

Wouldn't they still be able to connect whatever they wanted behind their NAT router? If it was that easy, the old rusty ISPs would have done it a long time ago!

User avatar
mhoppes
Associate
Associate
 
Posts: 664
Joined: Thu Apr 10, 2014 9:14 pm
Location: Pennsylvania
Has thanked: 10 times
Been thanked: 125 times

Re: Limit MAC Addresses

Tue Apr 21, 2015 12:03 pm

@wayneorack - Yes, that's fine. What this is designed to combat is someone connecting many devices to a switch port and overloading the MAC table in the switch/causing other issues on an EVC type of setup.

adair and I are both on the same page here..... Chris is going to curse and swear though :P

User avatar
wayneorack
Experienced Member
 
Posts: 129
Joined: Thu Sep 04, 2014 12:16 pm
Location: San Angelo, TX
Has thanked: 188 times
Been thanked: 64 times

Re: Limit MAC Addresses

Tue Apr 21, 2015 12:16 pm

mhoppes wrote:@wayneorack - Yes, that's fine. What this is designed to combat is someone connecting many devices to a switch port and overloading the MAC table in the switch/causing other issues on an EVC type of setup.


Duh! Thanks!

mhoppes wrote:.... Chris is going to curse and swear though :P


I like a good show! :popc:

User avatar
lligetfa
Associate
Associate
 
Posts: 1191
Joined: Sun Aug 03, 2014 12:12 pm
Location: Fort Frances Ont. Canada
Has thanked: 307 times
Been thanked: 381 times

Re: Limit MAC Addresses

Tue Apr 21, 2015 12:42 pm

wayneorack wrote:Wouldn't they still be able to connect whatever they wanted behind their NAT router? If it was that easy, the old rusty ISPs would have done it a long time ago!
That is an old cat-and-mouse game. You counter by setting TTL to 1. They counter by incrementing TTL on their router. You counter with 802.1X...

On my last job I had a problem where people were buying cheap switches and shoving them under their desk to connect printers they were not supposed to have. I also had IT coworkers (programmers) that thought they were network x-spurts buying cheap switches to add more ports. Another problem I had was unauthorized and undocumented moves. It was a chore to hunt down where the equipment was moved to.

I got tired of playing whack-a-mole, hunting the rogues down and planned to limit the switch ports to just one MAC to begin with and then later to lock it down so the MAC could not be moved by anyone but me. That was about the time all my coworkers got laid off and I didn't have the time to implement it. Also my budget got cut so I could not replace the old switches that would not support it.

User avatar
mhoppes
Associate
Associate
 
Posts: 664
Joined: Thu Apr 10, 2014 9:14 pm
Location: Pennsylvania
Has thanked: 10 times
Been thanked: 125 times

Re: Limit MAC Addresses

Tue Apr 21, 2015 12:55 pm

There's another perfect use of it, Les. I had not even though about that, but yes allowing only a specific MAC to attach (for example if I'm demarcing to a customer and want to limit what they may plug into a port)... or let's say at a shared tower site where the switch is not in an enclosure... I might disable all ports and MAC lock active ports so if someone plugs something else in they can't access the network.

User avatar
wayneorack
Experienced Member
 
Posts: 129
Joined: Thu Sep 04, 2014 12:16 pm
Location: San Angelo, TX
Has thanked: 188 times
Been thanked: 64 times

Re: Limit MAC Addresses

Tue Apr 21, 2015 2:31 pm

mhoppes wrote:)... or let's say at a shared tower site where the switch is not in an enclosure...


I think leaving the high amperage 48 VDC POE on all the time will fix that!

User avatar
mhoppes
Associate
Associate
 
Posts: 664
Joined: Thu Apr 10, 2014 9:14 pm
Location: Pennsylvania
Has thanked: 10 times
Been thanked: 125 times

Re: Limit MAC Addresses

Tue Apr 21, 2015 2:33 pm

That's the current solution... no pun.

User avatar
lligetfa
Associate
Associate
 
Posts: 1191
Joined: Sun Aug 03, 2014 12:12 pm
Location: Fort Frances Ont. Canada
Has thanked: 307 times
Been thanked: 381 times

Re: Limit MAC Addresses

Tue Apr 21, 2015 3:20 pm

wayneorack wrote:
mhoppes wrote:)... or let's say at a shared tower site where the switch is not in an enclosure...


I think leaving the high amperage 48 VDC POE on all the time will fix that!
That is like the ECM that SAT TV used to do to fry bootleg cards.

On my last job I had my Fluke NMS email me when a rogue MAC showed up on my network. With the Fluke WGA I could do a trace switchroute and find what port they connected on and disable the port and grab my walking stick I kept behind the door.

Next
Return to Hardware and software issues

Who is online

Users browsing this forum: sirhc and 48 guests