From mboxrd@z Thu Jan 1 00:00:00 1970 From: "Tariq Anwer" Subject: howto bind Mac to ip address Date: Mon, 11 Aug 2003 13:17:28 +0500 Sender: netfilter-admin@lists.netfilter.org Message-ID: <007601c35fe1$01eb3d20$142a45ca@shahid> Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="----=_NextPart_000_0073_01C3600A.E9BF1760" Return-path: Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: To: netfilter@lists.netfilter.org This is a multi-part message in MIME format. ------=_NextPart_000_0073_01C3600A.E9BF1760 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable Hi! I'm a new to Linux, I want to setup Linux NAT box for a small LAN with = selective services to allow like only browsing for staff and other = services for management like ftp msn chatting etc. =20 1.> I want to bind each MAC address to his or her assigned IP address = so nobody should mess around to change his or her IP's. =20 2.> I want to allow selective MAC addresses each time, so they are not = allowed to use it all the time or I can block them whenever I want to. =20 I will highly appreciate if anybody could help me or direct me to any = web site or article to build this Box successfully. =20 Best regards, =20 Alien ------=_NextPart_000_0073_01C3600A.E9BF1760 Content-Type: text/html; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable
Hi!
 

I=92m a new to Linux, = I want to=20 setup Linux NAT box for a small LAN with selective services to allow = like only=20 browsing for staff and other services for management like ftp msn = chatting=20 etc.

 

1.>  I want to bind each MAC address = to his or=20 her assigned IP address so nobody should mess around to change his or = her=20 IP=92s.

 

2.> I want to = allow selective=20 MAC addresses each time, so they are not allowed to use it all the time = or I can=20 block them whenever I want to.

 

I will highly = appreciate if=20 anybody could help me or direct me to any web site or article to build = this Box=20 successfully.

 

Best regards,

 

Alien

------=_NextPart_000_0073_01C3600A.E9BF1760-- From mboxrd@z Thu Jan 1 00:00:00 1970 From: "Paul Cousins" Subject: Re: [iptables] howto bind Mac to ip address Date: Mon, 11 Aug 2003 11:33:30 +0100 Sender: netfilter-admin@lists.netfilter.org Message-ID: <001101c35ff4$025cc900$0300a8c0@frodo> References: <007601c35fe1$01eb3d20$142a45ca@shahid> Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="----=_NextPart_000_000E_01C35FFC.63E73540" Return-path: Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: To: netfilter@lists.netfilter.org This is a multi-part message in MIME format. ------=_NextPart_000_000E_01C35FFC.63E73540 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable .> I want to bind each MAC address to his or her assigned IP address so = nobody should mess around to change his or her IP's. look into dhcpd from the internet consortium www.isc.org/products/DHCP/ = 99.9% of all linux release's come with so its a case of RTM and go from = there but its very easy to configure espically with something like = webmin. 2.> I want to allow selective MAC addresses each time, so they are not = allowed to use it all the time or I can block them whenever I want to. iptables can filter by mac address and ip adress so deny all users but = those you wish to allow. A script with an allow variable in it would be = you best bet as you coud add and remove users very quickly form the = script then simply run and you new rules will be implemented = immediately. simple cron scripts with drop or deny rules set to run at times you wish = to deny access will restrict the users. there may be an easy way not = sure?.=20 hope this points you in the rigth direction. ------------------------------------------------ Paul Cousins Canterbury Computer Services paul@canterburycomputerservices.co.uk ----- Original Message -----=20 From: Tariq Anwer=20 To: netfilter@lists.netfilter.org=20 Sent: Monday, August 11, 2003 9:17 AM Subject: [iptables] howto bind Mac to ip address Hi! I'm a new to Linux, I want to setup Linux NAT box for a small LAN with = selective services to allow like only browsing for staff and other = services for management like ftp msn chatting etc. =20 1.> I want to bind each MAC address to his or her assigned IP address = so nobody should mess around to change his or her IP's. =20 2.> I want to allow selective MAC addresses each time, so they are not = allowed to use it all the time or I can block them whenever I want to. =20 I will highly appreciate if anybody could help me or direct me to any = web site or article to build this Box successfully. =20 Best regards, =20 Alien ------=_NextPart_000_000E_01C35FFC.63E73540 Content-Type: text/html; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable
.>  I want to bind = each MAC=20 address to his or her assigned IP address so nobody should mess around = to change=20 his or her IP=92s.
 
look into = dhcpd from the=20 internet consortium www.isc.org/products/DHCP/= 99.9% of all linux release's come with so its a case of = RTM and=20 go from there but its very easy to configure espically with something = like=20 webmin.
 

2.> I want to = allow selective=20 MAC addresses each time, so they are not allowed to use it all the time = or I can=20 block them whenever I want to.

 

iptables can filter by mac address and ip adress so deny all = users but=20 those you wish to allow. A script with an allow variable in it would be = you best=20 bet as you coud add and remove users very quickly form the script then=20 simply run and you new rules will be implemented = immediately.

 

simple cron scripts with drop or deny rules set to run at times = you wish=20 to deny access will restrict the users. there may be an easy way not = sure?.=20

 

 

hope this points you in the rigth direction.

------------------------------------------------
Paul=20 Cousins
Canterbury Computer Services
paul@canterburycomp= uterservices.co.uk
 
 
----- Original Message -----
From:=20 Tariq = Anwer=20
To: netfilter@lists.netfilter.o= rg=20
Sent: Monday, August 11, 2003 = 9:17=20 AM
Subject: [iptables] howto bind = Mac to ip=20 address

Hi!
 

I=92m a new to = Linux, I want to=20 setup Linux NAT box for a small LAN with selective services to allow = like only=20 browsing for staff and other services for management like ftp msn = chatting=20 etc.

 

1.>  I want to bind each MAC = address to his=20 or her assigned IP address so nobody should mess around to change his = or her=20 IP=92s.

 

2.> I want to = allow=20 selective MAC addresses each time, so they are not allowed to use it = all the=20 time or I can block them whenever I want to.

 

I will highly = appreciate if=20 anybody could help me or direct me to any web site or article to build = this=20 Box successfully.

 

Best regards,

 

Alien

------=_NextPart_000_000E_01C35FFC.63E73540-- From mboxrd@z Thu Jan 1 00:00:00 1970 From: Ramin Dousti Subject: Re: howto bind Mac to ip address Date: Mon, 11 Aug 2003 09:05:08 -0400 Sender: netfilter-admin@lists.netfilter.org Message-ID: <20030811130508.GA11493@cannon.eng.us.uu.net> References: <007601c35fe1$01eb3d20$142a45ca@shahid> Mime-Version: 1.0 Return-path: Content-Disposition: inline In-Reply-To: <007601c35fe1$01eb3d20$142a45ca@shahid> Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit To: Tariq Anwer Cc: netfilter@lists.netfilter.org On Mon, Aug 11, 2003 at 01:17:28PM +0500, Tariq Anwer wrote: > Hi! Hello, You know that the MAC address is only visible on the same ethernet link. Having said this, How are the IP addresses being assigned? If it's by DHCP, then you can assign each MAC, a well-known IP and filter based on that IP... If not, then you must be on the same ethernet link and just use the the mac module (see "man iptables" and look for mac). Ramin > > I'm a new to Linux, I want to setup Linux NAT box for a small LAN with selective services to allow like only browsing for staff and other services for management like ftp msn chatting etc. > > > > 1.> I want to bind each MAC address to his or her assigned IP address so nobody should mess around to change his or her IP's. > > > > 2.> I want to allow selective MAC addresses each time, so they are not allowed to use it all the time or I can block them whenever I want to. > > > > I will highly appreciate if anybody could help me or direct me to any web site or article to build this Box successfully. > > > > Best regards, > > > > Alien From mboxrd@z Thu Jan 1 00:00:00 1970 From: Cedric Blancher Subject: Re: howto bind Mac to ip address Date: 11 Aug 2003 15:28:31 +0200 Sender: netfilter-admin@lists.netfilter.org Message-ID: <1060608510.765.39.camel@elendil.intranet.cartel-securite.net> References: <007601c35fe1$01eb3d20$142a45ca@shahid> <20030811130508.GA11493@cannon.eng.us.uu.net> Mime-Version: 1.0 Content-Transfer-Encoding: quoted-printable Return-path: In-Reply-To: <20030811130508.GA11493@cannon.eng.us.uu.net> Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="iso-8859-1" To: Ramin Dousti Cc: Tariq Anwer , netfilter@lists.netfilter.org Le lun 11/08/2003 =E0 15:05, Ramin Dousti a =E9crit : > You know that the MAC address is only visible on the same ethernet link. > Having said this, How are the IP addresses being assigned? If it's by > DHCP, then you can assign each MAC, a well-known IP and filter based on > that IP... A malicious user can reconfigure manually its interface, or use ARP cache poisoning to redirect trafic in order to listen/tamper/redirect trafic or spoof another host. A good way to enforce IP/MAC associations is static ARP cache : arp -s [-i ] Or : arp -f [-i ] This way, you're sure your firewall won't answer a request from an IP that uses a wrong MAC address. > If not, then you must be on the same ethernet link and just > use the the mac module (see "man iptables" and look for mac). Netfilter mac match brings a second security layer that is redundant with static ARP cache (redundancy is good for security stuff) especially for logging MAC address change attempts. --=20 http://www.netexit.com/~sid/ PGP KeyID: 157E98EE FingerPrint: FA62226DA9E72FA8AECAA240008B480E157E98EE From mboxrd@z Thu Jan 1 00:00:00 1970 From: Ramin Dousti Subject: Re: howto bind Mac to ip address Date: Mon, 11 Aug 2003 09:48:39 -0400 Sender: netfilter-admin@lists.netfilter.org Message-ID: <20030811134839.GC11493@cannon.eng.us.uu.net> References: <007601c35fe1$01eb3d20$142a45ca@shahid> <20030811130508.GA11493@cannon.eng.us.uu.net> <1060608510.765.39.camel@elendil.intranet.cartel-securite.net> Mime-Version: 1.0 Return-path: Content-Disposition: inline In-Reply-To: <1060608510.765.39.camel@elendil.intranet.cartel-securite.net> Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit To: Cedric Blancher Cc: Ramin Dousti , Tariq Anwer , netfilter@lists.netfilter.org On Mon, Aug 11, 2003 at 03:28:31PM +0200, Cedric Blancher wrote: > > You know that the MAC address is only visible on the same ethernet link. > > Having said this, How are the IP addresses being assigned? If it's by > > DHCP, then you can assign each MAC, a well-known IP and filter based on > > that IP... > > A malicious user can reconfigure manually its interface, or use ARP > cache poisoning to redirect trafic in order to listen/tamper/redirect > trafic or spoof another host. A good way to enforce IP/MAC associations > is static ARP cache : > > arp -s [-i ] > > Or : > > arp -f [-i ] > > This way, you're sure your firewall won't answer a request from an IP > that uses a wrong MAC address. Absolutely. But let's back off a bit and take a look at the picture as a whole. We're talking about the internal users here. If someone is so ambisious to do what you said, be sure they can do even more harm to you. Besides, are you going to implement this at every single router on any LAN segment you have internally? Or is this solution meant for VSOHO? But, your point taken :-) Ramin > > > If not, then you must be on the same ethernet link and just > > use the the mac module (see "man iptables" and look for mac). > > Netfilter mac match brings a second security layer that is redundant > with static ARP cache (redundancy is good for security stuff) especially > for logging MAC address change attempts. > > -- > http://www.netexit.com/~sid/ > PGP KeyID: 157E98EE FingerPrint: FA62226DA9E72FA8AECAA240008B480E157E98EE From mboxrd@z Thu Jan 1 00:00:00 1970 From: Cedric Blancher Subject: Re: howto bind Mac to ip address Date: 11 Aug 2003 16:08:53 +0200 Sender: netfilter-admin@lists.netfilter.org Message-ID: <1060610932.765.52.camel@elendil.intranet.cartel-securite.net> References: <007601c35fe1$01eb3d20$142a45ca@shahid> <20030811130508.GA11493@cannon.eng.us.uu.net> <1060608510.765.39.camel@elendil.intranet.cartel-securite.net> <20030811134839.GC11493@cannon.eng.us.uu.net> Mime-Version: 1.0 Content-Transfer-Encoding: quoted-printable Return-path: In-Reply-To: <20030811134839.GC11493@cannon.eng.us.uu.net> Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="iso-8859-1" To: Ramin Dousti Cc: Tariq Anwer , netfilter@lists.netfilter.org Le lun 11/08/2003 =E0 15:48, Ramin Dousti a =E9crit : > Absolutely. But let's back off a bit and take a look at the picture as = a whole. > We're talking about the internal users here. If someone is so ambisious= to do > what you said, be sure they can do even more harm to you. Without any doubt. This is a paranoid mesure to prevent mighty lusers or big evil 3lle7 crackers who managed to get into the LAN to mess around ;) > Besides, are you going to implement this at every single router on any > LAN segment you have internally? Or is this solution meant for VSOHO? Well, I do not think implementing a static ARP cache on the Linux NAT box will be more a burden than doing almost the same using iptables with mac match (as far as I understand what OP wants). I mean once you have done this for one purpose (e.g. DHCP MAC based assignement), there's not much left to do to generate a /etc/ethers like file for filling ARP cache or generate a basic iptables ruleset. > But, your point taken :-) Was just for info and discussion, not for contradiction. Most of the time, DHCP assignement as you told before is far sufficient to provide an acceptable way to associate MAC and IP. --=20 http://www.netexit.com/~sid/ PGP KeyID: 157E98EE FingerPrint: FA62226DA9E72FA8AECAA240008B480E157E98EE From mboxrd@z Thu Jan 1 00:00:00 1970 From: "Sebastian" Subject: RE: howto bind Mac to ip address Date: Mon, 11 Aug 2003 16:51:55 +0200 Sender: netfilter-admin@lists.netfilter.org Message-ID: <000701c36018$1bcb5d60$0200a8c0@basti79> References: <007601c35fe1$01eb3d20$142a45ca@shahid> Mime-Version: 1.0 Content-Transfer-Encoding: 7bit Return-path: In-Reply-To: <007601c35fe1$01eb3d20$142a45ca@shahid> Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="us-ascii" To: 'Tariq Anwer' , Netfilter Mailinglist Hi! Just a general hint. If I understand u correcty, you'll bind MAC- to IP-Adresses to apply different filters/restritions to each clients. But you have to keep in mind, if the users of the client systems have root privileges they are able to alter their MAC-Address with most modern Ethernet-Adapters. Also many Windows-Drivers have these capabilities, too. This could easily be used to bypass your resriction. Greets Sebastian. -----Original Message----- From: netfilter-admin@lists.netfilter.org [mailto:netfilter-admin@lists.netfilter.org] On Behalf Of Tariq Anwer Sent: Monday, August 11, 2003 10:17 AM To: netfilter@lists.netfilter.org Subject: howto bind Mac to ip address Hi! I'm a new to Linux, I want to setup Linux NAT box for a small LAN with selective services to allow like only browsing for staff and other services for management like ftp msn chatting etc. 1.> I want to bind each MAC address to his or her assigned IP address so nobody should mess around to change his or her IP's. 2.> I want to allow selective MAC addresses each time, so they are not allowed to use it all the time or I can block them whenever I want to. I will highly appreciate if anybody could help me or direct me to any web site or article to build this Box successfully. Best regards, Alien