• November 05, 2024, 02:31:48 AM
  • Welcome, Guest
Please login or register.

Login with username, password and session length
Advanced search  

News:

This Forum Beta is ONLY for registered owners of D-Link products in the USA for which we have created boards at this time.

Author Topic: Access Control when IP or MAC can be changed  (Read 2360 times)

Longs

  • Level 2 Member
  • **
  • Posts: 26
Access Control when IP or MAC can be changed
« on: December 31, 2011, 11:23:45 AM »

DIR655 with 1.33NA firmware.  I'm trying to determine how to block access to the internet for a specific LAN computer when the user knows how to change a MAC address.  I don't want to turn MAC control on and grant only to listed computers - the list doesn't accommodate enough MAC addresses, and the client has wireless and wired since it's a laptop.  I also don't want to set static IPs on all of the devices since some cannot accommodate that feature.

I'm thinking that reserving an IP address isn't ultimately the solution either, since assigning the IP isn't going to work if the MAC changes.

Any thoughts on how to use access control under these circumstances?

Thanks!
Logged

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: Access Control when IP or MAC can be changed
« Reply #1 on: December 31, 2011, 02:02:35 PM »

I would reserve the IP addresses anyways, however if they are changing the MAC addresses on there own then you need to ban the device from your network completely. I.e. disconnect the cable and don't provide Wifi password. It's hard to manage the router and effectively manage access control over a device if they are changing the MAC accress since the router options are kind of based on a MAC address string that usually doesn't change. The only way would be to watch the dynamic clients list and if you need a new mac address, change the reservation to reflect the change and add it to the list of Mac filters at set to NOT ALLOW. Might set up a schedule if you want to allow this person online at certain time frames of the day.

If there changing the MAC address on you then you need to figure out if you should ban them completely or make adjustments when they change the address. Not alot you can do with routers in the regards.

Let us know how it goes.
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.