Is there any way on ip firewall I can limit so the user won't be able to share internet more than two mac address.
I was to limit them and allow only specific range of ip they can use to go on Internet.
You can only allow certain address to use the internet, but if a user uses one of those addresses and performs NAT behind it... That as they say is that.
So if a user performs NAT behind a valid address you won't see the MAC address of any device except the head end device. This is the nature of layer 3.