[ previous ] [ next ] [ threads ]
 
 From:  Lee Sharp <leesharp at hal dash pc dot org>
 To:  "m0n0wall at lists dot m0n0 dot ch" <m0n0wall at lists dot m0n0 dot ch>
 Subject:  Re: [m0n0wall] deny certain mac address from getting an ip?
 Date:  Sun, 15 Jun 2008 12:47:54 -0500
YvesDM wrote:

> So I blocked all dest. p25 traffic from his ip of with a firewall rule on
> the LAN if (on top of the list, so above lan net->any) , but somehow he
> still manages to crash the system.

Note that blocking and rejecting are different.  Specifically, one 
creates a state.  Which are you doing?

As to assigning a bogus IP, I know the GUI does sanity checking, but 
does the config file?  What if you assign a static IP, save the config, 
change it in the config to 127.0.0.1, and upload the config?  Or just 
give it a totally invalid IP with no route to the firewall?

			Lee