Block device by manufacturer in MX network

MarcP
Kind of a big deal

Block device by manufacturer in MX network

Hi all,

 

Within a MX-only network, is there a way to block devices by its manufacturer automatically?

As we have no HP devices in our company I would like to block these (external technicians have them) devices instantly, when they connect theirselfs to the MX (they just want to check the internetconnection, but I don´t want them in our networks at any time).

 

Thanks, regards

Marc

3 Replies 3
PhilipDAth
Kind of a big deal
Kind of a big deal

If you have a typical configuration with unauthenticated ports - you can't block them.

 

You could enabled 802.1x port authentication and MAC address bypass and use something like FreeRADIUS and write a small script to permit or deny access by just the MAC address.

https://documentation.meraki.com/MX/Access_Control_and_Splash_Page/MX_Access_Policies_(802.1X)#MAC_a...

 

https://wiki.freeradius.org/guide/Mac-Auth

Actually you probably don't even need a script.  You could probably get away with a regular expression.

MarcP
Kind of a big deal

Thanks Phiip, I´ll try that

Get notified when there are additional replies to this discussion.