ETHERLINE
®
ACCESS NF04T | Version 1 | 04/16/20
35
8
MAC address filtering
With the function “MAC Filtering;” communication via the ETHERLINE
®
ACCESS NF04T can be limited to devices
with certain MAC addresses (“Whitelisting”) or devices with certain MAC addresses can be denied access
(“Blacklisting”).
MAC Filtering can be used both in the NAT and in the bridge operating mode.
Filtering for each MAC address can be activated on the WAN, on the LAN, or on both sides.
MAC addresses must always be entered in the format “AA:BB:CC:DD:EE:FF;” whereby numbers are to be indicated
with hexadecimals.
MAC Filtering has the highest priority of all filters in the ETHERLINE
®
ACCESS NF04T.
As soon as the first MAC address is entered in the MAC filter mode “Whitelist”, only frames from this MAC address
are allowed through, irrespective of all other packet filter rules.
When MAC Filtering is used in the “Whitelist” mode, the MAC addresses of
all
allowed devices must be indicated.
When MAC Filtering is used in the “Whitelist” mode, the MAC addresses of
all
allowed devices must be indicated.
If no MAC filter rule has been entered, the “MAC Filtering” is deactivated, irrespective of the “Default MAC Policy”.
In the NAT mode, the MAC filtering is only carried out WHEN the MAC address is also indicated in the IP header of
the packet. Layer 2 frames are not forwarded in the NAT mode.
The MAC filtering takes place on layer 2 in the bridge mode.
A maximum of 128 MAC filter rules can be defined.