Wildcard for MAC-Filters?

Bonny

Well-Known Member
OP
Member
Joined
Dec 8, 2008
Messages
825
Trophies
1
Location
Bavaria
XP
2,084
Country
Germany
I'am using an MAC-Address-Filter in my local WLAN-router. i know, it dosen't boost security much, but anyway... I got 2 chinese devices (Tablet & Smartphone) who change their MAC-Address every time they boot up. So i have to register them new every time :glare:

Question: Is the a way to enter a wildcard MAC Address into the router, so that he allows all addresses that (for example) start with 03:21:00 - And the last 3 values can be anything?

I already tried this...

03:21:00:**:**:**
03:21:00:??:??:??
03:21:00:*
03:21:00:**:**:**
03:21:00:

But the rounter dosen't accepted anyone of that...

Is there a solution for this Problem?
 

FAST6191

Techromancer
Editorial Team
Joined
Nov 21, 2005
Messages
36,798
Trophies
3
XP
28,321
Country
United Kingdom
Manual's page on mac filtering says only 20 devices so can't presumably do the create every viable one and go from there. If it is limited to 20 it probably does not have a fun thing in the HTML management setup. Can't rule out some undocumented function within telnet management or something.

That said why are using mac filtering? It is generally considered all but useless. Indeed the only use I have ever found is if you are doing some kind of isolated and free network setup (think two ports beside each computer, one able to access whatever it likes, the other locked to the network with all the goodies on, secure network mac blocked from internet one in case someone gets the bright idea to swap ports to get all the internet on the main supposed to be secure machine)

It looks like you can have up to 4 guest wifi networks. Can you maybe use one of those instead?

Alternatively maybe buy a secondary router and lock that down as necessary for the other devices.
 
  • Like
Reactions: Bonny

Bonny

Well-Known Member
OP
Member
Joined
Dec 8, 2008
Messages
825
Trophies
1
Location
Bavaria
XP
2,084
Country
Germany
Thanks for looking into my issue so deeply, i'll guess i'll set up an other Network for those 2 devices... or as you suggest: Maybe stop the whole MAC Filtering at all. Has it really no regarding in security at all?
 

FAST6191

Techromancer
Editorial Team
Joined
Nov 21, 2005
Messages
36,798
Trophies
3
XP
28,321
Country
United Kingdom
Maybe stop the whole MAC Filtering at all. Has it really no regarding in security at all?

Your experience alone says how sacred mac addresses really are.
In a technical sense then I guess Windows made it marginally harder to spoof them a few years back, though in practice... https://www.groovypost.com/howto/change-mac-address-windows-10-why/ . Linux, which is what runs all those nice wireless cracking programs, has no such qualms.

You might also get the security by obscurity factor. Today most will not likely have encountered mac address filtering and not immediately think to snatch it and fake one, and possibly knock another offline to steal theirs, though if they are blindly following a guide it will possibly include such a step. However security by obscurity is not security at all.

About the only use it has is allowing your friends or someone non technical to join your wifi and not have the change the password for all the other devices on it afterwards if you don't want them using it after they have gone. Assuming you don't need them to access network shares (though even then you might have options) you have guest network options for a reason though, several of them in this. With mac addresses you can do a few more fancy things in some routers (it will be one of the things many of the "free half hour, pay after that" type setups use, and those "fill in our survey/join our mailing list" thing you might get redirected to in a restaurant) but this is not that, though some consumer ones might allow you to assign bandwidth to different ones.
 
  • Like
Reactions: Bonny

Bonny

Well-Known Member
OP
Member
Joined
Dec 8, 2008
Messages
825
Trophies
1
Location
Bavaria
XP
2,084
Country
Germany
Your experience alone says how sacred mac addresses really are.
In a technical sense then I guess Windows made it marginally harder to spoof them a few years back, though in practice... https://www.groovypost.com/howto/change-mac-address-windows-10-why/ . Linux, which is what runs all those nice wireless cracking programs, has no such qualms.

You might also get the security by obscurity factor. Today most will not likely have encountered mac address filtering and not immediately think to snatch it and fake one, and possibly knock another offline to steal theirs, though if they are blindly following a guide it will possibly include such a step. However security by obscurity is not security at all.

About the only use it has is allowing your friends or someone non technical to join your wifi and not have the change the password for all the other devices on it afterwards if you don't want them using it after they have gone. Assuming you don't need them to access network shares (though even then you might have options) you have guest network options for a reason though, several of them in this. With mac addresses you can do a few more fancy things in some routers (it will be one of the things many of the "free half hour, pay after that" type setups use, and those "fill in our survey/join our mailing list" thing you might get redirected to in a restaurant) but this is not that, though some consumer ones might allow you to assign bandwidth to different ones.

Thanks for the detailed reply!
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • Maximumbeans @ Maximumbeans:
    I can't believe you got me with that
    +1
  • SylverReZ @ SylverReZ:
    I haven't been gaming for such a long time. Been mostly busy with sleep, hardware tinkering and checking GBAtemp frequently.
  • SylverReZ @ SylverReZ:
    Hope you've had a good morning.
  • Maximumbeans @ Maximumbeans:
    It's going alright thanks :) I know what you mean with gaming time. It's precious where I can get it these days.
    +1
  • Maximumbeans @ Maximumbeans:
    I think that's why I focus on just enjoying single player experiences that aren't too competitive
  • Maximumbeans @ Maximumbeans:
    How are you doing?
  • SylverReZ @ SylverReZ:
    There's also this thing where I'm hyperfocused at night and cannot get to sleep.
  • SylverReZ @ SylverReZ:
    @Maximumbeans, I'm doing alright, thanks.
    +1
  • Maximumbeans @ Maximumbeans:
    That must be rough. Productive I'm sure but hard to balance with daily life
    +1
  • SylverReZ @ SylverReZ:
    @Maximumbeans, Indeed. I've been working on getting this Infecutus chip to work on my PS2. But after soldering, I realised that a plastic piece was missing from the power ribbon cable to the power and eject buttons.
  • SylverReZ @ SylverReZ:
    Now I could go with soldering the contacts from the cable to the connector on the mobo, but doesn't sound like a good permanent solution.
  • Maximumbeans @ Maximumbeans:
    Man, that's beyond my brain :rofl: I'm no good with hardware for now. I'd like to get into hardmods in future though
  • SylverReZ @ SylverReZ:
    @Maximumbeans, Maybe start practice soldering. Get a cheap-ass soldering iron and follow some good YouTube tutorials.
    +1
  • SylverReZ @ SylverReZ:
    Least my experience has gotten better than over a decade ago. My iron would constantly bump into components and break them.
  • Maximumbeans @ Maximumbeans:
    Sounds good. I actually did soldering but like 16 years ago for school so uuuuh probably rusty haha
  • SylverReZ @ SylverReZ:
    @Maximumbeans, Same here. I did soldering at school from a teacher who I honestly liked since he had plenty of good electronics experience.
    +1
  • Maximumbeans @ Maximumbeans:
    I wish I could play chess well
    +1
  • Maximumbeans @ Maximumbeans:
    Useless but a true art
    +1
  • SylverReZ @ SylverReZ:
    @Maximumbeans, I had a friend who had a glass chess set for their birthday.
  • SylverReZ @ SylverReZ:
    It was like all clear and fancy. Tbf I'm not too experienced with chess, but would like to learn someday.
  • Maximumbeans @ Maximumbeans:
    That sounds really cool
  • Maximumbeans @ Maximumbeans:
    I know the basics but no strategy at all :rofl:
    Maximumbeans @ Maximumbeans: I know the basics but no strategy at all :rofl: