netfilter.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* Re: drop dhcp request from a particular mac address, after a dhcp relay
@ 2010-03-12  2:27 Ming-Ching Tiew
  2010-03-12  9:06 ` John Haxby
  2010-03-13  8:10 ` Mart Frauenlob
  0 siblings, 2 replies; 9+ messages in thread
From: Ming-Ching Tiew @ 2010-03-12  2:27 UTC (permalink / raw)
  To: netfilter, Robert Nichols

--- On Wed, 3/10/10, Robert Nichols <rnicholsNOSPAM@comcast.net> wrote:

 :-
> >
> >    iptables ..... -m bootp --mac-source
> 00:08:a1:ab:75:d1 -j DROP ?
> >
> > Well, if 'iptables' can't serve the purpose, how about
> ebtables ?
> 
> Wouldn't it be a lot easier to adjust the DHCP server's
> configuration by
> adding a "deny" statement in the pool's permit list?
> 

True but manually editing the configuration file will require the dhcp server to be restarted, whereas 'iptables' and/or 'ebtables' can be scripted at runtime.

Cheers. 




      

^ permalink raw reply	[flat|nested] 9+ messages in thread
* drop dhcp request from a particular mac address, after a dhcp relay
@ 2010-03-10 14:30 Ming-Ching Tiew
  2010-03-10 15:30 ` Robert Nichols
  0 siblings, 1 reply; 9+ messages in thread
From: Ming-Ching Tiew @ 2010-03-10 14:30 UTC (permalink / raw)
  To: netfilter


I would like to inhibit a dhcp request from a particular mac address, on the dhcp server.

If the client is directly LAN connected, I would suppose the following will work :-

iptables ....... -m mac --mac-source 

But to add a twist to the problem, the machine which must be blocked from obtaining a DHCP IP is connected to a DHCP relay, and therefore, the dhcp server is seeing only the mac adddress of the relay. Can this be accomplished with iptables ? 

Is there a match which works something like this :-

  iptables ..... -m bootp --mac-source 00:08:a1:ab:75:d1 -j DROP ?

Well, if 'iptables' can't serve the purpose, how about ebtables ?

Regards.




      

^ permalink raw reply	[flat|nested] 9+ messages in thread

end of thread, other threads:[~2010-03-14 21:36 UTC | newest]

Thread overview: 9+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2010-03-12  2:27 drop dhcp request from a particular mac address, after a dhcp relay Ming-Ching Tiew
2010-03-12  9:06 ` John Haxby
2010-03-13  8:10 ` Mart Frauenlob
2010-03-13 16:03   ` Robert Nichols
2010-03-13 16:34     ` Mart Frauenlob
2010-03-13 19:29     ` Sven-Haegar Koch
2010-03-14 21:36       ` Robert Nichols
  -- strict thread matches above, loose matches on Subject: below --
2010-03-10 14:30 Ming-Ching Tiew
2010-03-10 15:30 ` Robert Nichols

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).