[USG Flex H] - Whitelisting/Blocklisting MACs address to join into network

Options
Maverick87
Maverick87 Posts: 180 image  Master Member
5 Answers First Comment Friend Collector

Hello everyone,
there is a possibility to whitelist or blocklist some mac address to join into network?

I mean, if I would like to deny some mac address (on an physical eth or on a Wifi AP) to prevent to access to my network/subnet/VLAN, there is a possibility to deny or allow a mac address to join into?

I can allow/deny some services based on an IP Address, but in this case I need an IP reservation and I need to know the mac address beforehand.

Thank you

Accepted Solution

  • Zyxel_Melen
    Zyxel_Melen Posts: 4,929 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate
    Answer ✓
    Options

    Hi @Maverick87

    I checked with our team and confirmed the MAC based address object is still under evaluation.

    The current method for MAC address:

    • Whitelist:
      • Setup the static DHCP table first and change the DHCP server pool size to the amount of static DHCP table. This should allow the DHCP server won't provide IP address to non-authorized device.
      • Enable IP spoofing prevention. Remember the "Include DHCP Leasing Entries" also need to be selected/enabled. (Prevent to connect to the firewall and Internet)
      • Enable ARP Spoofing Prevention in system > advanced setting. (Prevent LAN forwarding traffic)
    • Blocklist:
      • Device Insight (Static/fixed MAC address device only).
    Zyxel Melen


All Replies

  • Zyxel_Melen
    Zyxel_Melen Posts: 4,929 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate
    Options

    Hi @Maverick87

    If you focus on USG FLEX H, rather than adding a switch to setup MAC authentication, then you might need to:

    1. Setup the static DHCP table first and change the DHCP server pool size to the amount of static DHCP table. This should allow the DHCP server won't provide IP address to non-authorized device.
    2. Enable IP spoofing prevention. Remember the "Include DHCP Leasing Entries" also need to be selected/enabled. (Prevent to connect to the firewall and Internet)
    3. Enable ARP Spoofing Prevention in system > advanced setting. (Prevent LAN forwarding traffic)

    Hope this helps.

    Zyxel Melen


  • Maverick87
    Maverick87 Posts: 180 image  Master Member
    5 Answers First Comment Friend Collector
    Options

    Hi @Zyxel_Melen,
    but is not possible to implement a mac address object (also, if I remember well, I've created already an idea about this) and prevent that the mac address object don't receive the DHCP from the interface?

    Thanks

  • PeterUK
    PeterUK Posts: 4,564 image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary
    Options

    So here the thing it should be possible to make a stateful firewall with everything MAC,IP, Port which is not the same as switch that can do ACL with everything MAC,IP, Port.

    So can the USG hardware do with everything MAC,IP, Port as a stateful firewall? Or how about a stateful firewall IP, Port with ACL MAC?

  • Zyxel_Melen
    Zyxel_Melen Posts: 4,929 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate
    Answer ✓
    Options

    Hi @Maverick87

    I checked with our team and confirmed the MAC based address object is still under evaluation.

    The current method for MAC address:

    • Whitelist:
      • Setup the static DHCP table first and change the DHCP server pool size to the amount of static DHCP table. This should allow the DHCP server won't provide IP address to non-authorized device.
      • Enable IP spoofing prevention. Remember the "Include DHCP Leasing Entries" also need to be selected/enabled. (Prevent to connect to the firewall and Internet)
      • Enable ARP Spoofing Prevention in system > advanced setting. (Prevent LAN forwarding traffic)
    • Blocklist:
      • Device Insight (Static/fixed MAC address device only).
    Zyxel Melen


  • Zyxel_Melen
    Zyxel_Melen Posts: 4,929 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate
    Options

    Hi @PeterUK

    Currently, USG FLEX H series supports to operate/control MAC, IP, and Port, but the current MAC-based methods only offer full pass or full block operation (Device Insight); more refined control is still under evaluation.

    Zyxel Melen