Mac address filtering on ATP/USG

Options
DiegoF
DiegoF Posts: 4
Friend Collector
edited August 2022 in Security Ideas
it would be very useful to be able to create security policies based on mac address objects. In Zyxel firewall there is no possibility to create mac address objects like in other vendors firewall. Is this a feature you plan to implement on your firewalls as well?
2 votes

Active · Last Updated

Comments

  • dpipro
    dpipro Posts: 64  ZCNE Certified
    First Anniversary ZCNE Switch Level 1 Certification - 2020 ZCNE Nebula Level 1 Certification - 2020 ZCNE Security Level 1 Certification - 2019
    Options
    Hello @DiegoF

    as a workaround you can configure IP/MAC binding to specify a fixed IP to each MAC address.

    Best regards
    Best regards
  • DiegoF
    DiegoF Posts: 4
    Friend Collector
    Options
    Hello @dpipro
    thanks for the suggestion, for a small enviroment your workaround it's ok but i need this feature for deploying firewall in school with hundreds of student's device

    Best regards
  • PeterUK
    PeterUK Posts: 2,716  Guru Member
    First Anniversary 10 Comments Friend Collector First Answer
    Options
    Why not use a switch?
  • DiegoF
    DiegoF Posts: 4
    Friend Collector
    Options
    PeterUK said:
    Why not use a switch?
    the need is for wireless client, many hundreds
  • dpipro
    dpipro Posts: 64  ZCNE Certified
    First Anniversary ZCNE Switch Level 1 Certification - 2020 ZCNE Nebula Level 1 Certification - 2020 ZCNE Security Level 1 Certification - 2019
    Options
    Hello @DiegoF

    you can configure a dedicated wireless SSID for students with an associated VLAN in a different subnet. With this configuration you can isolate the students network from the LAN and you can add security policies for them. What you think?

    Best regards
  • PeterUK
    PeterUK Posts: 2,716  Guru Member
    First Anniversary 10 Comments Friend Collector First Answer
    Options
    DiegoF said:
    PeterUK said:
    Why not use a switch?
    the need is for wireless client, many hundreds
    That does not stop from using a switch for MAC filtering you can go from  ATP/USG  to switch to AP or you can get a AP with filtering. 
  • Nazareno
    Options
    Hi, i'm looking for the same issue.. I need to create mac address filter on dhcp, so only authorized MAC address can connect to the lan...

  • PeterUK
    PeterUK Posts: 2,716  Guru Member
    First Anniversary 10 Comments Friend Collector First Answer
    edited October 2022
    Options
    Nazareno said:
    Hi, i'm looking for the same issue.. I need to create mac address filter on dhcp, so only authorized MAC address can connect to the lan...

    You can do this in the VPN300

    However this does not stop DHCP from getting a IP by DHCP....