From owner-freebsd-questions@FreeBSD.ORG Mon Sep 24 21:55:42 2007 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id AED6916A419 for ; Mon, 24 Sep 2007 21:55:42 +0000 (UTC) (envelope-from fbsd.questions@rachie.is-a-geek.net) Received: from sarevok.dnr.servegame.org (b83183.upc-b.chello.nl [212.83.83.183]) by mx1.freebsd.org (Postfix) with ESMTP id 741DE13C469 for ; Mon, 24 Sep 2007 21:55:42 +0000 (UTC) (envelope-from fbsd.questions@rachie.is-a-geek.net) Received: from snoogles.rachie.is-a-geek.net (unknown [66.230.99.27]) by sarevok.dnr.servegame.org (Postfix) with ESMTP id 333F9B8E4 for ; Mon, 24 Sep 2007 23:55:41 +0200 (CEST) Received: from localhost (localhost [127.0.0.1]) by snoogles.rachie.is-a-geek.net (Postfix) with ESMTP id 37B841CDEE for ; Mon, 24 Sep 2007 13:55:39 -0800 (AKDT) From: Mel To: freebsd-questions@freebsd.org Date: Mon, 24 Sep 2007 23:55:36 +0200 User-Agent: KMail/1.9.7 References: <020301c7fef2$7e8a1db0$6501a8c0@GRANT> In-Reply-To: MIME-Version: 1.0 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: 7bit Content-Disposition: inline Message-Id: <200709242355.37331.fbsd.questions@rachie.is-a-geek.net> Subject: Re: Silly IPFW question. X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 24 Sep 2007 21:55:42 -0000 On Monday 24 September 2007 23:44:07 Chuck Swiger wrote: > On Sep 24, 2007, at 2:33 PM, Grant Peel wrote: > > Is there anyway to make a rule in IPFW that will match MAC > > addresses instead of IP or port numnbers (and no, I didnt see > > anything in the docs :-)) > > Search "man ipfw" for MAC. Something like this will: > > ipfw add 10 deny MAC any 10:20:30:40:50:60 > > ...block any traffic from that ethernet address. Be aware of the > net.link.ether.ipfw sysctl needed and advice in the section "PACKET > FLOW". Ok, been too long since I played with IPFW obviously. -- Mel