<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Can I deny/block a mac address in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/can-i-deny-block-a-mac-address/m-p/520726#M107927</link>
    <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a PA-440 firewall that has a rogue router that keeps popping up in the DHCP monitor. I was wanting to know if there is a way to block the mac address of this rogue device as it keeps causing issues.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Joe&lt;/P&gt;</description>
    <pubDate>Wed, 09 Nov 2022 00:14:06 GMT</pubDate>
    <dc:creator>joecastillo</dc:creator>
    <dc:date>2022-11-09T00:14:06Z</dc:date>
    <item>
      <title>Can I deny/block a mac address</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-i-deny-block-a-mac-address/m-p/520726#M107927</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a PA-440 firewall that has a rogue router that keeps popping up in the DHCP monitor. I was wanting to know if there is a way to block the mac address of this rogue device as it keeps causing issues.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Joe&lt;/P&gt;</description>
      <pubDate>Wed, 09 Nov 2022 00:14:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-i-deny-block-a-mac-address/m-p/520726#M107927</guid>
      <dc:creator>joecastillo</dc:creator>
      <dc:date>2022-11-09T00:14:06Z</dc:date>
    </item>
    <item>
      <title>Re: Can I deny/block a mac address</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-i-deny-block-a-mac-address/m-p/520750#M107933</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/108733"&gt;@joecastillo&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks for the post.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Firewall does not have an option to block MAC address. If there is a switch in between, I would block it there by configuring static MAC address table entry with drop action. If that is not the option, then I can only think of creating a fake ARP entry on Firewall Interface side:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGrCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGrCAK&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Wed, 09 Nov 2022 06:44:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-i-deny-block-a-mac-address/m-p/520750#M107933</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2022-11-09T06:44:10Z</dc:date>
    </item>
    <item>
      <title>Re: Can I deny/block a mac address</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-i-deny-block-a-mac-address/m-p/520785#M107948</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/108733"&gt;@joecastillo&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Seems like a simple solution would be to create a static DHCP reservation (reserved address if using PA-440s DHCP server) for the router's MAC and just create a security rule at the top of your rulebase denying all traffic to/from that address.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'd personally be taking care of this on the switch feeding this client if you can however. Anything you do directly on the firewall is just going to be denying traffic to/from the router, it isn't going to be preventing the router or anyone connected to it from communicating to other LAN hosts unless you're already taking care of that side of things. I'd be shutting down the associated switch port, when someone complains you've found out who's doing it and they'd need to remove it before the interface is turned back on. Good time to start thinking about NAC/802.1x however.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Nov 2022 13:45:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-i-deny-block-a-mac-address/m-p/520785#M107948</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2022-11-09T13:45:16Z</dc:date>
    </item>
    <item>
      <title>Re: Can I deny/block a mac address</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-i-deny-block-a-mac-address/m-p/521510#M108070</link>
      <description>&lt;P&gt;Thank you I will give this a try.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Nov 2022 03:34:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-i-deny-block-a-mac-address/m-p/521510#M108070</guid>
      <dc:creator>joecastillo</dc:creator>
      <dc:date>2022-11-17T03:34:50Z</dc:date>
    </item>
  </channel>
</rss>

