RE: [fw-wiz] Link level security with static arp tables

From: Sloane, David (DSloane_at_vfa.com)
Date: 10/14/03

  • Next message: Martin A. Brown: "Re: [fw-wiz] Link level security with static arp tables"
    To: <firewall-wizards@honor.icsalabs.com>
    Date: Mon, 13 Oct 2003 18:12:57 -0400
    
    

    Would it be easier to solve this at a switch? If you have a switch
    capable of filtering by mac-address (or mac-based VLANS), you'll
    probably get better performance all around. The last time I talked to a
    Cisco tech about VLAN options, I was told that VLAN's on Cisco switches
    perform best using MAC-address lists.

    So a VLAN could isolate the traffic. Or an access-list. It depends on
    your switch and what kind of filtering it supports.

    -David

    -----Original Message-----
    From: firewall-wizards-admin@honor.icsalabs.com
    [mailto:firewall-wizards-admin@honor.icsalabs.com] On Behalf Of Debian
    User
    Sent: October 12, 2003 8:32 AM
    To: firewall-wizards@honor.icsalabs.com
    Subject: [fw-wiz] Link level security with static arp tables

    Hello,

    Problem:

    [ INET ] ---- <eth1> [ NAT GATEWAY ] <eth0> --- [ LOCAL NET, 50 clients
    ]

    I need to limit access to the gateway according to allowed MACs, ie
    Ethernet
    frames from allowed MAC addresses are forwarded to and fro in the
    gateway,
    but others will be dropped (and logged if possible).

    I could disable arp on eht0 and use static arp tables in the gw, but
    that
    would mean that the gateway won't answer any arp queries, hence the
    clients
    will not be able to find it's MAC. Setting up static arp tables in
    clients is
    not an option.

    I could use netfilter MAC matching support in the kernel, but that would
    mean
    I have to add 50 rules to the ruleset adding considerable overhead.
    Moreover,
    it is a link level problem that sould be solved in the same level, so
    netfilter is not an attractive option. Please comment if I'm wrong.

    Any solutions?

    _______________________________________________
    firewall-wizards mailing list firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Martin A. Brown: "Re: [fw-wiz] Link level security with static arp tables"

    Relevant Pages

    • RE: Different terms for the same or more secure?
      ... A SWITCH is a box with a bunch of interfaces and a MAC address ... has seen that packet's source MAC address show up at interface X, ... of those groups is a VLAN. ...
      (Security-Basics)
    • Re: Blocking by MAC Address -
      ... Again an attacker could still bypass 802.1x with this configuration. ... Switch will only see one MAC. ... > the ideia is to change dynamicaly the VLAN of the port. ...
      (microsoft.public.windows.server.networking)
    • RE: Windows 2000 Static arp not static
      ... The switch still sees the offending machine as having the correct ... MAC address and the victim as having the correct MAC address. ... One that detects these ARP flip-flops. ... unless you meant static arp entries. ...
      (Focus-Microsoft)
    • SNMPv3 and Community String Indexing
      ... read mac addresses from vlan 3 with snmpv2: ... when i read the switch with username and password and v3, ... receive macs from the default vlan. ...
      (comp.dcom.sys.cisco)
    • Re: Catalyst 3750 with 2 vlans. Only vlan1 drop packet when ping
      ... when I ping to the ip onvlan1, about 10% come back with "Request ... Are you pinging the hsrp vlan 1 address, ... ping vlan 140's interface with no problems? ... how does the other switch know how to get ...
      (comp.dcom.sys.cisco)