- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
05-17-2017 01:19 PM
Hello,
I was interested if there was a way to block a mac address of a device for malicious behavior? Bacially if i have a user on a guest connection and they are searching things they shouldnt, they could be blocked for 5 minutes or whatever and then return to the network. I know its a strange request but I was curious to see if it could be done.
Thanks 🙂
05-17-2017 01:38 PM - edited 05-17-2017 01:40 PM
MAC address blocking is not a good way to control users as it is easy to spoof. For the guest control, you could implement a separate VLAN, basic security policy (allowing a minimum for internet browsing), as well as implement a URL filtering with other security profiles.
05-17-2017 01:22 PM
This topic was started in the Community Feedback area, and is related to the Palo Alto Networks devices. Because of that I am moving this to the General topics area.
05-17-2017 01:38 PM - edited 05-17-2017 01:40 PM
MAC address blocking is not a good way to control users as it is easy to spoof. For the guest control, you could implement a separate VLAN, basic security policy (allowing a minimum for internet browsing), as well as implement a URL filtering with other security profiles.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!