I thought the MAC implementation was meant to check the MAC address along with the IP address before the traffic was allowed. The feature request Network Security: MAC-Based Packet Filter Rules is pretty specific.
As you can see from the screenshots, I have changed my MAC but the traffic is still flowing freely.
Screenshots:
1. Define a host with with MAC 02:aa:bb:cc[:D]d:ee and IP 192.168.0.179
2. Create a rule to allow traffic from that host.
3. Traffic from different MAC with same IP is allowed.
Regards
Bill