Articles Articles Most Popular Articles Most Popular Articles Most Helpful Articles Most Helpful Articles
DrillDown Icon Table of Contents Back
 . . . . . . . . . . . . .
DrillDown Icon What's New
DrillDown Icon Knowledge Base Information
DrillDown Icon Cyberoam UTM
DrillDown Icon Product Literature
DrillDown Icon Best Practices & Policies
DrillDown Icon Protect Your Cyberoam Appliances from Power Fluctuations
DrillDown Icon Version 10.x
DrillDown Icon Version 9.x
DrillDown Icon How To
DrillDown Icon Anti Spam
DrillDown Icon Anti Virus
DrillDown Icon Authentication
DrillDown Icon Blocking
DrillDown Icon Block the Internet access based on MAC address
DrillDown Icon Allow specific URL from the blocked Category
DrillDown Icon Block Gmail
DrillDown Icon Allow specific URLs
DrillDown Icon Filter HTTPS URLs
DrillDown Icon Block Free Anonymous Web Proxy (kproxy) over HTTPS Using Custom IDP Signature
DrillDown Icon Block Rediff Bol IM Using IDP Signature
DrillDown Icon Block SKYPE using IDP signature
DrillDown Icon Block Google Talk IM using Custom IDP Signature
DrillDown Icon Block External Proxy using IDP
DrillDown Icon Block Unauthorized Internet Access By Using Anonymous Proxies
DrillDown Icon Block Windows Live Messenger using IDP
DrillDown Icon Block Chikka Mobile Instant Messenger
DrillDown Icon Block ORKUT
DrillDown Icon Block a specific URL
DrillDown Icon Clients
DrillDown Icon Content filtering
DrillDown Icon Firewall
DrillDown Icon IPS
DrillDown Icon Logs & Reports
DrillDown Icon SNMP
DrillDown Icon System
DrillDown Icon Registration
DrillDown Icon User
DrillDown Icon VPN
DrillDown Icon Intimation Regarding US New Daylight Saving Time Support
DrillDown Icon Verify the integrity check of Cyberoam Upgrade file using MD5 checksum
DrillDown Icon Troubleshooting
DrillDown Icon FAQ
DrillDown Icon Tech Notes
DrillDown Icon Visio Stencils
DrillDown Icon Glossary
DrillDown Icon Product Technical Support
DrillDown Icon Compatibility
DrillDown Icon Cyberoam Virtual UTM
DrillDown Icon Endpoint Data Protection
DrillDown Icon Cyberoam SSL VPN
DrillDown Icon Cyberoam iView
DrillDown Icon Cyberoam Central Console
DrillDown Icon Cyberoam's On-Cloud Management Service
  Email This ArticlePrintPrint Current Article and All Sub-Articles
Rate Icon Rate Icon Rate Icon Rate Icon Rate Icon
 
Block the Internet access based on MAC address


Applicable version – 9.6.0 build 16 onwards

MAC address filtering is more secure than IP address filtering as MAC address is rarely changed.

In DHCP environment, IP address changes dynamically and hence MAC address is more reliable to identify source and destination of the network traffic.

In wireless environment, common security measure to prevent the unwanted network access is MAC address filtering. Here the router is configured to accept traffic from specific MAC addresses only and whitelisted devices are assigned new IP addresses through DHCP. This way they retain their ability to communicate with the Network. Any attempt to communicate by masquerading the IP address will blocked as attacker’s computer’s MAC address will not match with the MAC address of the whitelisted devices.

The article provides the steps to block the Internet access based on MAC address. Entire configuration is to be done through the Web Admin console of Cyberoam.

Step 1. Add Host

Go to Firewall à Host à Add and add host with the following parameters:
Host name - mypc
MAC address – As per your requirement 
 


Alternately, host can be added at the time of configuring firewall rule also.

Step 2. Create LAN to WAN zone firewall rule

Go to Firewall à Create Rule and create a firewall rule with the following parameters:
Source – LAN/mypc (host as created in step 1)
Destination – WAN/Any Host
Service/Service Group – All Services (Change if required)
Apply Schedule – As per your requirement
Action - Drop




In the similar manner, access can be blocked for multiple MAC addresses also.

Above configuration will block the Internet access for any user whose request is coming from the MAC address ‘00-1D-09-DF-84-54’.

Please note that MAC address of the original requestor is replaced with the MAC address of the firewall, router or layer 3 switch when the request is routed through them. So if the user is not directly connected through Cyberoam, Cyberoam will not receive the MAC address of the original requester. In such cases, use user-MAC binding to block the Internet access as specified How do I enable User/MAC binding?

Document version – 1.0-15/07/2009

Attachments
Article ID: 1313