Re: FireQOS matching by MAC address
"Tsaousis, Costa" <[email protected]>
| Newsgroups | gmane.comp.security.firewalls.firehol.user |
|---|---|
| Message-ID | <CANL+VpY5UiAQzZ2mMrXU6H6aGj=hJ81SnSZCepzSXncQNPAAkA@mail.gmail.com> |
Hi Phineas, I just pushed a version of fireqos that support srcmac and dstmac parameters. I cannot test it. I just verified the rules are accepted by the kernel. As always you can add multiple MAC addresses in a single parameter, enclosed in quotes. Could you please test it and report back success or failure? I generated rules according to http://www.docum.org/faq/cache/62.html Thanks. Costa On Sun, Aug 17, 2014 at 3:49 PM, Phineas Gage <[email protected]> wrote: > It would be nice to be able to create a “match” rule in FireQOS to match > traffic by MAC address. > > I’m interested in this because we’ll be transitioning to a dual-stack > network with both IPv4 and IPv6 support. Currently, we assign IPv4 > addresses using DHCP (some are assigned fixed addresses, and others put > into different pools), then in fireqos.conf classify using “match src” and > “match dst” rules with IP addresses. I know this isn’t bulletproof, but > since I control all of the hosts, it works. With IPv6, we'll get a /64 > address from our ISP, which can’t be subnetted further, and I suppose we’ll > be using SLAAC instead of DHCP (haven’t sorted that out yet). So, the only > way I can think of to do traffic classification on a per-host basis is > using the MAC address. > > Anything I’m missing? > > _______________________________________________ > Firehol-support mailing list > [email protected] > http://lists.firehol.org/mailman/listinfo/firehol-support > _______________________________________________ Firehol-support mailing list [email protected] http://lists.firehol.org/mailman/listinfo/firehol-support