Community discussions

MikroTik App
 
DjAtif
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 68
Joined: Thu Jan 29, 2009 5:22 pm

How to stop MAC Cloning

Thu Feb 05, 2009 2:25 pm

Hello i have a problem i have more then 50 clients have there own speed limitation but the mostly clients change the NIC mac address to other clients & using internet i want to stop MAC cloneing how? i have option for hotspot & proxy but i want to provide internet in same method i.e now i m using simple NAT anyone have a idea thanks in advanced
 
User avatar
normis
MikroTik Support
MikroTik Support
Posts: 26376
Joined: Fri May 28, 2004 11:04 am
Location: Riga, Latvia

Re: How to stop MAC Cloning

Thu Feb 05, 2009 2:32 pm

if you will have any kind of user/pass based authentication (like hotspot or pppoe) then the mac cloning will be useless for these violators, they will also need username+password
 
DjAtif
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 68
Joined: Thu Jan 29, 2009 5:22 pm

Re: How to stop MAC Cloning

Thu Feb 05, 2009 5:18 pm

no i m using just simpale NAT by firewall masqeurade & i can't change into hotspot or pppe any one have idea??
 
Mplsguy
MikroTik Support
MikroTik Support
Posts: 227
Joined: Fri Jun 06, 2008 5:06 pm

Re: How to stop MAC Cloning

Thu Feb 05, 2009 10:34 pm

If all your client devices are running RouterOS, you can use management frame protection available in wireless-test:
http://wiki.mikrotik.com/wiki/Wireless_ ... protection

Or you can use WPA and assign different preshared key for every customer.
 
mudasir
Member Candidate
Member Candidate
Posts: 278
Joined: Tue Apr 29, 2008 3:38 am
Location: Karachi, Pakistan
Contact:

Re: How to stop MAC Cloning

Fri Feb 06, 2009 6:13 pm

AOA,

Dear Atif,

why can not you implement to PPPoE or Hotspot, they are the best authentication methods. Where are you running your cable internet system
 
onowojemma
Member Candidate
Member Candidate
Posts: 129
Joined: Sun Sep 11, 2005 5:27 pm
Location: Nigeria

Re: How to stop MAC Cloning

Fri Aug 05, 2011 6:38 pm

if you will have any kind of user/pass based authentication (like hotspot or pppoe) then the mac cloning will be useless for these violators, they will also need username+password
Hello normis i run hotspot but in my school student still do mac cloning and bypass the hotspot is there nay way i could handle this?
Thanks
 
Feklar
Forum Guru
Forum Guru
Posts: 1724
Joined: Tue Dec 01, 2009 11:46 pm

Re: How to stop MAC Cloning

Fri Aug 05, 2011 7:58 pm

if you will have any kind of user/pass based authentication (like hotspot or pppoe) then the mac cloning will be useless for these violators, they will also need username+password
Hello normis i run hotspot but in my school student still do mac cloning and bypass the hotspot is there nay way i could handle this?
Thanks
The only way to prevent MAC spoofing on a layer2 network is to prevent each client from seeing each other. This is beyond the control and scope of ANY layer3 device, this must happen at the edge of the network. Get access points that support client isolation, get managed switches that support port isolation, this is your solution.

Note that this does not prevent them from changing their MAC address at will, it just prevents them from scanning the network and finding out other peoples MAC addresses in the hopes of getting on with another clients MAC address.
 
onowojemma
Member Candidate
Member Candidate
Posts: 129
Joined: Sun Sep 11, 2005 5:27 pm
Location: Nigeria

Re: How to stop MAC Cloning

Fri Aug 05, 2011 10:36 pm

if you will have any kind of user/pass based authentication (like hotspot or pppoe) then the mac cloning will be useless for these violators, they will also need username+password
Hello normis i run hotspot but in my school student still do mac cloning and bypass the hotspot is there nay way i could handle this?
Thanks
The only way to prevent MAC spoofing on a layer2 network is to prevent each client from seeing each other. This is beyond the control and scope of ANY layer3 device, this must happen at the edge of the network. Get access points that support client isolation, get managed switches that support port isolation, this is your solution.

Note that this does not prevent them from changing their MAC address at will, it just prevents them from scanning the network and finding out other peoples MAC addresses in the hopes of getting on with another clients MAC address.
Yea thanks for ur reply but could i use mikrotik to do that ?
 
ahang
Frequent Visitor
Frequent Visitor
Posts: 59
Joined: Tue Apr 06, 2010 1:16 am
Location: 127.0.0.1

Re: How to stop MAC Cloning

Sun Aug 07, 2011 6:55 pm

For pppoe spoofing MAC is not working :)
 
User avatar
Davis
Member Candidate
Member Candidate
Posts: 117
Joined: Mon Aug 01, 2011 12:27 pm
Location: Latvia, Riga
Contact:

Re: How to stop MAC Cloning

Mon Aug 08, 2011 8:01 am

In Russia some providers use PPTP VPN (warning it uses CPU on VPN server/router) because its more secure than PPPoE.
If you don't want any username/password authentication for your users you can use managed switch with MAC filtering (each user then would be connected to his own port on managed switch and only packets from his MAC address would be accepted on that port). This would eliminate MAC cloning completely (yes, managed switch can eliminate MAC spoofing/cloning).
If the only problem is that users cheat their speed limits and you have a few standard speed limits (lets say 2/2, 10/10 and 20/20 Mbps) for all your customers in some cases cheaper alternative woud be isolating groups of users with similar speed limits. For example if you have 3 standard speed limits (example above), all your customers are connected to one port of your router and it has 2 unused ports you can connect all users with 2/2 limit to unused port 1 and all users with 10/10 limit to unused port 2. Bridge these ports together and in BRIDGE filter rules input chain (or if you want to use ip firewall filter specify in-bridge-port there) put IP or MAC restrictions to these ports (be aware that DHCP will also use 0.0.0.0 as source address). An alternative to bridging would be putting clients with different speed limits in different subnets (or some nasty configuration with big drawbacks). In case of different subnets there won't be many filtering rules but IP address will have to be changed along with speed limit. If your router doesn't have enaugh free ports attach managed switch to it and use VLANs (or set IP/MAC restrictions on the switch). In any case cheaper method will have drawback that you must also physically connect user to another layer 2 (switch) network when changing speed limit.
If you have long lines with many chained switches don't think about 1 big managed switch, but think about replacing your small unmanaged switches with small managed switches that support MAC filtering (e.g. MikroTik RB250GS).
In any case you must also ensure physical security of switches (that users won't plug their cords to different ports or networks).
 
Feklar
Forum Guru
Forum Guru
Posts: 1724
Joined: Tue Dec 01, 2009 11:46 pm

Re: How to stop MAC Cloning

Mon Aug 08, 2011 5:03 pm


Yea thanks for ur reply but could i use mikrotik to do that ?
If the MikroTik is the edge device, i.e. the access point yes. Or if a client needs to go "through" the MikroTik to talk to another client, you can block them.

If it's just the layer3 hop on the network to the internet then no. A client does not need to use a router to talk to other devices on the same layer2 network.
 
nmthaker
Member Candidate
Member Candidate
Posts: 145
Joined: Wed Jan 05, 2011 6:10 am

Re: How to stop MAC Cloning

Thu Oct 10, 2013 12:37 pm

Dear Sir,

I have PPPoE user name and password but some other person using the same MAC and login. Can you please help us to clear the issue with MAC Spoofing.
 
sswfarm
just joined
Posts: 5
Joined: Wed Jan 23, 2013 8:52 pm

Re: How to stop MAC Cloning

Tue Feb 11, 2014 9:30 pm

if you will have any kind of user/pass based authentication (like hotspot or pppoe) then the mac cloning will be useless for these violators, they will also need username+password
Wrong!!!At least on Hotspot anyway.
 
plisken
Forum Guru
Forum Guru
Posts: 2509
Joined: Sun May 15, 2011 12:24 am
Location: Belgium
Contact:

Re: How to stop MAC Cloning

Wed Feb 12, 2014 12:02 pm

If all your client devices are running RouterOS, you can use management frame protection available in wireless-test:
http://wiki.mikrotik.com/wiki/Wireless_ ... protection

Or you can use WPA and assign different preshared key for every customer.
@Mplsguy Link does not exist
 
User avatar
normis
MikroTik Support
MikroTik Support
Posts: 26376
Joined: Fri May 28, 2004 11:04 am
Location: Riga, Latvia

Re: How to stop MAC Cloning

Wed Feb 12, 2014 12:13 pm

If all your client devices are running RouterOS, you can use management frame protection available in wireless-test:
http://wiki.mikrotik.com/wiki/Wireless_ ... protection

Or you can use WPA and assign different preshared key for every customer.
@Mplsguy Link does not exist
That's what happens when you respond to a 5 year old post ;-)

http://wiki.mikrotik.com/wiki/Manual:In ... protection
 
plisken
Forum Guru
Forum Guru
Posts: 2509
Joined: Sun May 15, 2011 12:24 am
Location: Belgium
Contact:

Re: How to stop MAC Cloning

Wed Feb 12, 2014 12:19 pm

Thanks Normis :D

Who is online

Users browsing this forum: Google [Bot], js02sixty, llamajaja and 73 guests