Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
pfSense Forum
pfSense English Support
»
Captive Portal
»
Strange behaviour with MAC passthrough
Username:
Password:
1 Hour
1 Day
1 Week
1 Month
Forever
Home
Help
Search
Login
Register
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: Strange behaviour with MAC passthrough (Read 1313 times)
0 Members and 1 Guest are viewing this topic.
Floddy
Newbie
Offline
Posts: 12
Strange behaviour with MAC passthrough
«
on:
March 24, 2012, 01:20:13 pm »
Hello,
My setup on the captive portal net is this:
[pfsense box nic]---[wlan AP (access point)] [wlan AP in client mode]---[TV]
+ additional laptops connecting to the pfsense box through the wlan AP.
The TV obviously gets no connectivity to the oustside world unless I let it pass through the captive portal. But, this is the strange thing: If I enter the TV's MAC, it doesn't work. If I enter the TV's wlan AP's MAC though, it works, even if the TVs MAC isn't entered. I really don't understand why? The calls comes from the TV, so, shouldn't the TV be the ones that should be let throght?
Entering the TV and the TV AP's mac addresses for static DHCP works as a charm.
Thanks,
Floddy
Logged
cmb
Administrator
Hero Member
Online
Posts: 6035
Re: Strange behaviour with MAC passthrough
«
Reply #1 on:
March 24, 2012, 03:11:37 pm »
Only one MAC can be seen from any one wireless client, so what your second WLAN box is doing is translating the source MAC to its own MAC. It leaves the MAC within DHCP requests alone, basically acting as a DHCP relay of sorts, which is why it gets its own IP. That's typical behavior in such scenarios.
Logged
pfSense Commercial Support
Paying customers receive support priority and as in depth of assistance as desired through the official commercial support channels at portal.pfsense.org. Forum users receive as much help as time permits.
Floddy
Newbie
Offline
Posts: 12
Re: Strange behaviour with MAC passthrough
«
Reply #2 on:
March 26, 2012, 10:23:29 am »
Ah, ok, that explains it.
Does that apply only to APs in client mode, or the other "regular" AP as well, like the one connected directly to the pfsense box?
For example, I have a laptop with windows firewall rules that lets smb traffic through, but only if it's from my regular computer. But, if one would just play with the thought that windows firewall could filter on mac instead of IP addresses; would that work, or would it just see the APs mac?
Thanks,
Floddy
Logged
cmb
Administrator
Hero Member
Online
Posts: 6035
Re: Strange behaviour with MAC passthrough
«
Reply #3 on:
March 26, 2012, 04:16:28 pm »
Only applies to devices behind a wireless device in client mode. In a typical AP scenario with multiple clients, those clients all retain their real MAC address.
Logged
pfSense Commercial Support
Paying customers receive support priority and as in depth of assistance as desired through the official commercial support channels at portal.pfsense.org. Forum users receive as much help as time permits.
jimp
Administrator
Hero Member
Offline
Posts: 12808
Re: Strange behaviour with MAC passthrough
«
Reply #4 on:
April 02, 2012, 03:21:42 pm »
There are some APs out there that work in a bridge mode where they don't forward on the client's MAC. I have a couple of them, EDIMAX somethingorother model. It's impossible to use more than one client from behind it in AP client mode from what I could tell.
Logged
Need help fast?
Commercial Support
!
Co-Author of
pfSense: The Definitive Guide
. - Check the
Doc Wiki
for FAQs.
Do not PM for help!
Donate to the project
|
My Wish List
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
Administrative
-----------------------------
=> Forum rules
=> Messages from the pfSense Team
=> Feedback
-----------------------------
pfSense English Support
-----------------------------
=> Installation and Upgrades
=> General Questions
=> 2.1 Snapshot Feedback and Problems
=> Post a bounty
===> Completed Bounties
===> Expired/Withdrawn Bounties
=> Hardware
=> Firewalling
=> NAT
=> CARP/VIPs
=> Routing and Multi WAN
=> Traffic Shaping
=> DHCP and DNS
=> IPv6
=> IPsec
=> PPTP
=> PPPoE Server
=> Captive Portal
=> webGUI
=> Wireless
=> SNMP
=> Packages
=> Virtualization installations and techniques
=> OpenVPN
=> Gaming
-----------------------------
Development/Documentation
-----------------------------
=> Documentation
=> Development
-----------------------------
General Category
-----------------------------
=> General Discussion
-----------------------------
International Support
-----------------------------
=> Indonesian
=> Deutsch
=> Español
=> Français
=> Italiano
=> Russian
=> Nederlands
=> Norwegian
=> Portuguese
=> Polish
=> Romanian
=> Swedish
=> Turkish
-----------------------------
Retired
-----------------------------
=> 1.2.3-PRERELEASE-TESTING snapshots - RETIRED
=> 1.2.1-RC Snapshot Feedback and Problems-RETIRED
=> 2.0-RC Snapshot Feedback and Problems - RETIRED
=> DNS Server testing area - RETIRED
Loading...