Community discussions

MikroTik App
 
YordanY1
just joined
Topic Author
Posts: 20
Joined: Tue Sep 07, 2021 2:54 am
Location: Bulgaria

Log when a specific MAC connect ?

Tue Oct 12, 2021 2:05 pm

Hello.

I have a list of MAC addresses which I would like to log when they connect to WAN from Internet.
Is this possible, and how ?

Thank You in advance.
 
holvoetn
Member Candidate
Member Candidate
Posts: 125
Joined: Tue Apr 13, 2021 2:14 am
Location: Belgium

Re: Log when a specific MAC connect ?

Tue Oct 12, 2021 4:47 pm

My take:
Depends on the size of your list.
Firewall raw rule, prerouting, and then 1 rule per src MAC address with action log.
Not sure you can use a list for MAC addresses ... but this creation process can be made easier a bit with some smart scripting.

Isn't it more logical to log simply all connections from WAN (should be done anyhow for monitoring, I think ?) and then only filter out those MAC addresses you specifically need for your purpose ?
 
tdw
Forum Guru
Forum Guru
Posts: 1021
Joined: Sat May 05, 2018 11:55 am

Re: Log when a specific MAC connect ?

Tue Oct 12, 2021 5:11 pm

If the connections are to your WAN from the Internet MAC addresses will not available.
 
holvoetn
Member Candidate
Member Candidate
Posts: 125
Joined: Tue Apr 13, 2021 2:14 am
Location: Belgium

Re: Log when a specific MAC connect ?

Tue Oct 12, 2021 5:31 pm

If the connections are to your WAN from the Internet MAC addresses will not available.
Damn, didn't know that.
 
User avatar
anav
Forum Guru
Forum Guru
Posts: 8775
Joined: Sun Feb 18, 2018 11:28 pm
Location: Nova Scotia, Canada
Contact:

Re: Log when a specific MAC connect ?

Tue Oct 12, 2021 5:57 pm

If the connections are to your WAN from the Internet MAC addresses will not available.
Damn, didn't know that.
Oh not to worry, there will be far too many opportunities to re-live that reality. :-)
I'd rather manage rats than software. Follow my advice at your own risk! (Sob & mkx forced me to write that!)
MTUNA Certified, by the Ascerbic Llama!
 
holvoetn
Member Candidate
Member Candidate
Posts: 125
Joined: Tue Apr 13, 2021 2:14 am
Location: Belgium

Re: Log when a specific MAC connect ?

Tue Oct 12, 2021 6:24 pm

Damn, didn't know that.
Oh not to worry, there will be far too many opportunities to re-live that reality. :-)
:lol:
 
YordanY1
just joined
Topic Author
Posts: 20
Joined: Tue Sep 07, 2021 2:54 am
Location: Bulgaria

Re: Log when a specific MAC connect ?

Tue Oct 12, 2021 9:13 pm

O.. well.. So it is not possible ? :'(
Pity.
Actually I maybe made the question too general.
The situation is as follow :
- I have a Dahua NVR, and when someone connect to it - I need to log it's MAC address, and if the MAC is not in a specific list - to deny access.
( if this give a better options )
 
tdw
Forum Guru
Forum Guru
Posts: 1021
Joined: Sat May 05, 2018 11:55 am

Re: Log when a specific MAC connect ?

Tue Oct 12, 2021 9:50 pm

MAC addresses are only relevant within an ethernet / layer-2 network, once the IP contents a router and forwarded elsewhere the originating MAC address is no longer known.

Within any individual router the MAC-to-IP mappings are known for the locally-attached ethernet networks, if you wish to control access to your NVR from devices on a local network you can use MAC source addresses, but not for remote devices as the information is just not available.

Using MAC addresses for authorisation is generally a bad idea - they are easily spoofed allowing other to impersonate a 'trusted' device, and more recently Android & iOS have introduced random fake MAC addresses when you connect to a WiFi network to prevent your MAC address from being tracked.

The correct way of setting up limited remote access would be to create a VPN server on your Mikrotik, and provide credentials and/or certificates to remote users.
 
YordanY1
just joined
Topic Author
Posts: 20
Joined: Tue Sep 07, 2021 2:54 am
Location: Bulgaria

Re: Log when a specific MAC connect ?

Wed Oct 13, 2021 12:09 am

:|
Now as You wrote this and I did a research on it, seems like You are right on this.
Thank You guys !

Who is online

Users browsing this forum: lexart51 and 22 guests