Community discussions

MikroTik App
 
ferassk
just joined
Topic Author
Posts: 9
Joined: Tue Feb 18, 2014 4:52 pm

Can i hide user MAC address?

Mon Feb 13, 2017 12:03 pm

HI everybody
any idea to hide user MAC address?
i have many hackers trying to scan my network searching to any MAC cokes active user, So they change their MAC using some programs and login using the stalled MAC.
I'am trying to find any idea to HIDE the MAC address.
please help
 
User avatar
cdiedrich
Forum Veteran
Forum Veteran
Posts: 997
Joined: Thu Feb 13, 2014 2:03 pm
Location: Basel, Switzerland // Bremen, Germany
Contact:

Re: Can i hide user MAC address?

Mon Feb 13, 2017 1:36 pm

Well, hiding MAC addresses would break your network :-)
I guess you're talking about a wireless hotspot, right?
I would do it this way:

Set your DHCP server to add ARP entries for leases.
Set your LAN-facing interface to reply-only arp.
Stop client2client communication (default forward in w/l settings)
If you're using multiple w/l interfaces added to a bridge, give all of them the same bridge horizon, this stops inter-port-communication on the bridge.
If still necessary, add bridge filters to drop any arp request coming in from client-facing interfaces leaving the bridge on other client-facing interfaces.

This still won't stop attacker's ability to spoof mac addresses, but will make it more difficult.

-Chris
 
ferassk
just joined
Topic Author
Posts: 9
Joined: Tue Feb 18, 2014 4:52 pm

Re: Can i hide user MAC address?

Wed Feb 15, 2017 1:29 pm

Well, hiding MAC addresses would break your network :-)
I guess you're talking about a wireless hotspot, right?
I would do it this way:

Set your DHCP server to add ARP entries for leases.
Set your LAN-facing interface to reply-only arp.
Stop client2client communication (default forward in w/l settings)
If you're using multiple w/l interfaces added to a bridge, give all of them the same bridge horizon, this stops inter-port-communication on the bridge.
If still necessary, add bridge filters to drop any arp request coming in from client-facing interfaces leaving the bridge on other client-facing interfaces.

This still won't stop attacker's ability to spoof mac addresses, but will make it more difficult.

-Chris
Mr. Chris
Thanks a lot for answering my post
i'll try and inform u
feras
 
arkan7rb
just joined
Posts: 3
Joined: Wed Oct 05, 2016 10:46 pm

Re: Can i hide user MAC address?

Wed Aug 09, 2017 3:00 am

can you give me some bridge filter for droping arp request coming from vlans in bridge with other vlans so they wont know clients macs on other vlans because of the bridge

Who is online

Users browsing this forum: amarmerk, flyr, scoobyn8 and 48 guests