Daniel Hammer
2004-03-22 20:08:05 UTC
Subject: RE: [IPCop-devel] Mac filtering cababilities v2
Date: Mon, 22 Mar 2004 10:49:02 -0800
Maybe we can solve this problem by just subnetting your network to allow
the required connections, and then setup a MAC filter for each IP, that
way when someone takes the old system, the new one won't get the IP
until the NEW guy signs the list, and hands you his MAC. If they try
and fake a MAC to get a valid IP then you have issues, but filtering on
a MAC address would have this issue in IPTables as well, and be much
more shell configuration then just using the IPCop management pages.
Plus creating custom rulesets based on MAC for iptables would be much
more headache to manage then just a subnetted DHCP MAC list with almost
exactly the same drawbacks.
How Many total rooms, or Ethernet connections do you support?
There are 60 rooms and 60 connectionsDate: Mon, 22 Mar 2004 10:49:02 -0800
Maybe we can solve this problem by just subnetting your network to allow
the required connections, and then setup a MAC filter for each IP, that
way when someone takes the old system, the new one won't get the IP
until the NEW guy signs the list, and hands you his MAC. If they try
and fake a MAC to get a valid IP then you have issues, but filtering on
a MAC address would have this issue in IPTables as well, and be much
more shell configuration then just using the IPCop management pages.
Plus creating custom rulesets based on MAC for iptables would be much
more headache to manage then just a subnetted DHCP MAC list with almost
exactly the same drawbacks.
How Many total rooms, or Ethernet connections do you support?
How often is there any change or new lines run to new dorms?
Monthly.Do you already have a list of the current MAC addresses in use?
Yes.(around 50 users currently)Trevor
Sounds like you have a good idea, but I don't know how to implement it, haveonly heard little about subnetting(But will read, when finished writing).
And I just assumed (doh) that since the Ipcop was in charge of all
connections it would be an easy 'compare to' setup for the mac-adresses.
But if this works it would be great.
Thanx in advance
DH
_________________________________________________________________
Få alle de nye og sjove ikoner med MSN Messenger http://messenger.msn.dk