Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

IP or MAC, which one takes precedence in rules

When we build a definition using MAC(and IP as UTM doesn't allow mac-only rules), which value takes precedence?.

for example:
i have rule A from X station blocking everything.
then Rule B from Y (ip only) allowing only a certain URL.
then rule C from Z (ip/mac), allowing everything.

what happens when/if station X changes IP to the one that Y has/had and then Z?
theoretically it should keep triggering only the "X" rule as the MAC is unchanged, but that happens in Y case where it has only been defined as an IP host?, will it trigger both rules erroneously?


This thread was automatically locked due to age.
Parents
  • Do you mean the following rules in the following order?
    [LIST=1]X -> Any -> Any : Drop
    • Y -> Any -> {specific FQDN} : Allow
    • Z(MAC=XX:X:XX:XX:XX:XX) -> Any -> Any : Allow
    [/LIST]
    If so, then if X changes to the IP of Y, the second rule applies.

    If X changes to the IP of Z, then none of those rules apply.  If X also spoofs the MAC address of Z, then the third rule applies.

    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • Do you mean the following rules in the following order?
    [LIST=1]X -> Any -> Any : Drop
    • Y -> Any -> {specific FQDN} : Allow
    • Z(MAC=XX:X:XX:XX:XX:XX) -> Any -> Any : Allow
    [/LIST]
    If so, then if X changes to the IP of Y, the second rule applies.

    If X changes to the IP of Z, then none of those rules apply.  If X also spoofs the MAC address of Z, then the third rule applies.

    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
No Data
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?