Hi. I have a set of Mac addresses, for which I'd like to block traffic unless they are logged in.
I'd simultaneously like to avoid this setup in the firewall screen:
- Let authenticated users through (Rule 1)
- Block all unauthenticated users (Rule 2)
Because I have an army of machines on the network I'd prefer remain unaffected by this condition.
My first instinct was to create a clientless group for these MAC addresses, but it appears that the clientless group supersedes the client-based authentication. My log was full of:
"User abc failed to login to Firewall through authentication mechanism from 192.168.168.33 because of Already login as clientless user"
Thank you!
This thread was automatically locked due to age.