Maciek Kurkiewicz wrote:>>http://www.shorewall.net/configuration_file_basics.htm and look for
"Using
>>MAC Addresses".
>
>
> But there is nothing how to link each used MAC addres with suitable IP
> adress.
No -- that is not a feature of Shorewall.
> I know that i can write mac in blaclist file but I want to reject all
others
> mac''s and ip''s. I have to write all possible mac addres
whitch i need to
> reject ?
You can also use MAC addresses as the source in rules.
You will probably have to write an Extension Script
(http://www.shorewall.net/shorewall_extension_scripts.htm) if you want to
enforce MAC<->IP correspondence using Shorewall.
-Tom
--
Tom Eastep \ Shorewall - iptables made easy
AIM: tmeastep \ http://www.shorewall.net
ICQ: #60745924 \ teastep@shorewall.net