?
Solved

iptables

Posted on 2001-09-14
7
Medium Priority
?
386 Views
Last Modified: 2012-05-04
I need an expamle of how to make a rule with an IP and MAC addressess on iptables for Linux.
0
Comment
Question by:CyberGod
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
  • 2
7 Comments
 
LVL 5

Accepted Solution

by:
BlackDiamond earned 300 total points
ID: 6483687
iptables -A INPUT -s 2.3.4.0/24 -m mac --mac-source 00:11:22:33:44:55 -j ACCEPT
0
 

Author Comment

by:CyberGod
ID: 6484413
Can you be more specific about this -m mac --mac-source
0
 
LVL 51

Expert Comment

by:ahoffmann
ID: 6484736
does
   man iptables
not give you the answer
0
Tutorial: Introduction to Managing a Linux Server

In this tutorial on systemd, we will explore:
-OS/Distro Adoption
-chkconfig and Other Legacy Commands
-Summary and Key Commands

 
LVL 5

Expert Comment

by:BlackDiamond
ID: 6485092
CyberGod,
"-m mac" tells iptables that you want to use the built-in mac module, and that module has the --mac-source parameter.  The rule that I showed above would accept anything originating from the 2.3.4.0 subnet that was routed through an interface in the same broadcast domain (on the same subnet) with mac 00:11:22:33:44:55.

As ahoffmann stated, "man iptables" will show you all of these options.
0
 

Author Comment

by:CyberGod
ID: 6485504
iptables -A INPUT -s 2.3.4.5/32 -m mac --mac-source 00:11:22:33:44:55 -j ACCEPT

Does this means that I can accept packets from a NIC with IP 2.3.4.5 and MAC 00:11:22:33:44:55 ? (yes/no)
0
 
LVL 5

Expert Comment

by:BlackDiamond
ID: 6487901
Cybergod, that is correct.  But keep in mind that if you have more than one subnet, then you will need to use ip ranges combined with the MAC of your router interface.  This is because MAC addresses are seen in the same broadcast domain, so you will see the MAC address of the last device to touch the packet (which would be your router).  
0
 
LVL 51

Expert Comment

by:ahoffmann
ID: 6488055
BTW, would be nice to see what happens with such an iptables configuration with clients comming from a TokenRing network (where you need to set the MAC).
0

Featured Post

NEW Veeam Agent for Microsoft Windows

Backup and recover physical and cloud-based servers and workstations, as well as endpoint devices that belong to remote users. Avoid downtime and data loss quickly and easily for Windows-based physical or public cloud-based workloads!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

You ever wonder how to backup Linux system files just like Windows System Restore?  Well you can use Timeshift in Linux to perform those similar action.  This tutorial will show you how to backup your system files and keep regular intervals. Note…
Google Drive is extremely cheap offsite storage, and it's even possible to get extra storage for free for two years.  You can use the free account 15GB, and if you have an Android device..when you install Google Drive for the first time it will give…
Learn several ways to interact with files and get file information from the bash shell. ls lists the contents of a directory: Using the -a flag displays hidden files: Using the -l flag formats the output in a long list: The file command gives us mor…
Learn how to find files with the shell using the find and locate commands. Use locate to find a needle in a haystack.: With locate, check if the file still exists.: Use find to get the actual location of the file.:
Suggested Courses
Course of the Month9 days, 13 hours left to enroll

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question