USG 1000 block by mac address
All Replies
-
The USG can't block by MAC so you have two options:
get a managed switch and ACL by MAC.
use the IP/MAC Binding in the USG to give the MAC a fixed IP you can block in the firewall.
1 -
Peter,I have a managed switch..so I'll investigate that option.Regarding the ip/mac binding, I was playing with that on a local USG 1000 in my office, and locked myself out of the router. Luckily I had backed up my startup-config and recovered nicely..However I couldn't figure out how to block in the firewall.Should I create an address using Objects, then use that object name in the firewall?Thanks again for your input.0
-
Yes but you need the ip/mac binding to make that MAC be fixed to a IP
Should I create an address using Objects, then use that object name in the firewall?
Doing it by managed switch would stop the MAC getting a IP but if it changes its MAC it be allowed again even if not they can set a fixed IP and have access to the subnet.
do you know if the device on your network is connected to a switch port?0
Categories
- All Categories
- 415 Beta Program
- 2.4K Nebula
- 147 Nebula Ideas
- 96 Nebula Status and Incidents
- 5.7K Security
- 262 USG FLEX H Series
- 271 Security Ideas
- 1.4K Switch
- 74 Switch Ideas
- 1.1K Wireless
- 40 Wireless Ideas
- 6.4K Consumer Product
- 249 Service & License
- 387 News and Release
- 84 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.5K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 85 About Community
- 73 Security Highlight