How to restrict IP for authorized devices on Ethernet LAN/

Post new topic   Reply to topic    DD-WRT Forum Index -> Marvell MVEBU based Hardware (WRT1900AC etc.)
Goto page 1, 2  Next
Author Message
e123enitan
DD-WRT Novice


Joined: 13 Mar 2017
Posts: 46

PostPosted: Tue Sep 05, 2017 17:13    Post subject: How to restrict IP for authorized devices on Ethernet LAN/ Reply with quote
Hi Guys, I am a novice and new to DD WRT, so I will appreciate your kind advices.

I have configure my DD WRT, following most instructions on Youtube and here and there, so far it looks good.
What I am trying to achieve is to configure DD WRT not to assign IP to any devices that is trying to via ethernet jack in any room.

5 have five rooms, with enthernet jack for connecting SIP phone. When I 'm not at home my kids friends will removed the SIP Phone jack , then connect their laptop to connect to internet.

How could I prevent any foreign devices that are not setup in the static lease not obtain IP, let alone connect to my LAN/WAN network

Thanks for your suggestions
Sponsor
ScottieRotten
DD-WRT Novice


Joined: 31 Aug 2017
Posts: 8

PostPosted: Tue Sep 05, 2017 18:13    Post subject: Reply with quote
MAC filtering will do what you want. You will just have to make it so your devices MAC addresses are authorized. I would even go a step further and assign ip's to those devices.
e123enitan
DD-WRT Novice


Joined: 13 Mar 2017
Posts: 46

PostPosted: Tue Sep 05, 2017 18:20    Post subject: Reply with quote
ScottieRotten wrote:
MAC filtering will do what you want. You will just have to make it so your devices MAC addresses are authorized. I would even go a step further and assign ip's to those devices.



Thanks,
How do I get into this section of MAC filtering, I can see the wireless option, which is not what I needed.
Secondly how many devices could added if you know.
Also, could I disable DHCP, and enable static mode since all my devices at set in static lease table, would that work?

Cheers for your feed back, most appreciated
DaveI
DD-WRT User


Joined: 06 Jul 2009
Posts: 333

PostPosted: Tue Sep 05, 2017 18:40    Post subject: Reply with quote
Originally I also thought MAC Address filtering would work but it seems it only works for WIRELESS clients. Unless someone else knows a way to make MAC Address filtering work on the Ethernet Ports the OP would have to make all clients and devices connect wirelessly and unplug all the ethernet connections. Then MAC address filtering would work by adding the MAC addresses of only the devices he wanted to be able to connect. But I doubt he wants to give up ethernet for wireless (I wouldn't).
Per Yngve Berg
DD-WRT Guru


Joined: 13 Aug 2013
Posts: 6870
Location: Romerike, Norway

PostPosted: Tue Sep 05, 2017 19:28    Post subject: Reply with quote
802.1X Port Based Authentication is a feature available in managed switches.

Is all the devices connected directly to the dd-wrt router?

You could put the SIP Phones on a separate VLAN/Sub-net that does not have general internet access.
e123enitan
DD-WRT Novice


Joined: 13 Mar 2017
Posts: 46

PostPosted: Tue Sep 05, 2017 20:44    Post subject: Reply with quote
Per Yngve Berg wrote:
802.1X Port Based Authentication is a feature available in managed switches.

Is all the devices connected directly to the dd-wrt router?

You could put the SIP Phones on a separate VLAN/Sub-net that does not have general internet access.


That would be a good idea, but how do I configure that.

IP is set in block of 192.168.1.100 to 115 for the media clients
192.168.1.116 to 120 for cameras and 192.168.1.120 to 126 for phones

if its possible to configure vlan that would be nice BUT I have no clue how to achieve this settings

I have Linksys AC1900 v1 which I believe is able to handle the stress of the network pass through.

Please I help, I am willing to learn.

Thanks for your kind supports
e123enitan
DD-WRT Novice


Joined: 13 Mar 2017
Posts: 46

PostPosted: Tue Sep 05, 2017 20:51    Post subject: Reply with quote
e123enitan wrote:
Per Yngve Berg wrote:
802.1X Port Based Authentication is a feature available in managed switches.

Is all the devices connected directly to the dd-wrt router?

You could put the SIP Phones on a separate VLAN/Sub-net that does not have general internet access.


That would be a good idea, but how do I configure that.

IP is set in block of 192.168.1.100 to 115 for the media clients
192.168.1.116 to 120 for cameras and 192.168.1.120 to 126 for phones

All these devices are connected to a PC server that host the Telephone Server, Camera Server and Emby Media Server. all on the same network

if its possible to configure vlan that would be nice BUT I have no clue how to achieve this settings

I have Linksys AC1900 v1 which I believe is able to handle the stress of the network pass through.

Please I help, I am willing to learn.

Thanks for your kind supports
Per Yngve Berg
DD-WRT Guru


Joined: 13 Aug 2013
Posts: 6870
Location: Romerike, Norway

PostPosted: Tue Sep 05, 2017 21:14    Post subject: Reply with quote
Can't you do it with the Access Restrictions Tab in the GUI?
e123enitan
DD-WRT Novice


Joined: 13 Mar 2017
Posts: 46

PostPosted: Tue Sep 05, 2017 21:20    Post subject: Reply with quote
Per Yngve Berg wrote:
Can't you do it with the Access Restrictions Tab in the GUI?


How do I configure this, pls share more info how to configure this process.
e123enitan
DD-WRT Novice


Joined: 13 Mar 2017
Posts: 46

PostPosted: Tue Sep 05, 2017 21:51    Post subject: Reply with quote
Access restrictions would allow someone to get into my local network, but prevent access to Internet.
What I want is to prevent access to LAN network.
DaveI
DD-WRT User


Joined: 06 Jul 2009
Posts: 333

PostPosted: Tue Sep 05, 2017 23:42    Post subject: Reply with quote
What Per Yngve Berg stated would only work if you had a Managed Switch and setup VLANs...

What you could do if the little buggers don't have access to any ethernet ports other than the one they remove the SIP adapter from is to disconnect that one ethernet port from the main router/switch which would kill the internet at that port for the SIP adapter. Then either configure the SIP adapter to use wireless and enable MAC address filtering and enter the MAC address for the SIP adapter in the MAC Address filter section of DD-WRT. Or if wired access is required for the SIP Adapter move the SIP adapter to another location where the ethernet port can be secured (Locked rooms). Not a perfect solution as it would require making all areas with ethernet ports needing to be locked except for the one ethernet port you disconnected which is currently in use for the SIP Adapter.
DaveI
DD-WRT User


Joined: 06 Jul 2009
Posts: 333

PostPosted: Wed Sep 06, 2017 0:30    Post subject: Reply with quote
And there is one more low-tech way of dealing with this...You can Zip-Tie each end of the Ethernet cord. First Drill two small holes through the face plate of the ethernet port that has the SIP Adapter. Tightly wrap a zip-tie around the ethernet cord right by the RJ-45 connector and pass it through the holes you drilled in the face plate. Then pull the zip closed making sure there's no freefreeplay. Now the ethernet cord cannot be removed from the facplate. Reinstall the faceplate. Now you have to do the same thing on the SIP Adapter drilling two small holes in the platic case and wrapping the zip-tie around the ethernet cord on the end that plugs into the SIP Adapter...Then pass it through the two holes you drilled in the SIP adapter case (You'll need to remove the case to do this...Then pull everything tightly so the cord can't be removed from the SIP adapter. Then put the case on. This will stop them from being able to remove the cord from either the ethernet jack or the SIP adapter. Low-tech but it would work.
e123enitan
DD-WRT Novice


Joined: 13 Mar 2017
Posts: 46

PostPosted: Wed Sep 06, 2017 12:58    Post subject: Reply with quote
DaveI wrote:
What Per Yngve Berg stated would only work if you had a Managed Switch and setup VLANs...

What you could do if the little buggers don't have access to any ethernet ports other than the one they remove the SIP adapter from is to disconnect that one ethernet port from the main router/switch which would kill the internet at that port for the SIP adapter. Then either configure the SIP adapter to use wireless and enable MAC address filtering and enter the MAC address for the SIP adapter in the MAC Address filter section of DD-WRT. Or if wired access is required for the SIP Adapter move the SIP adapter to another location where the ethernet port can be secured (Locked rooms). Not a perfect solution as it would require making all areas with ethernet ports needing to be locked except for the one ethernet port you disconnected which is currently in use for the SIP Adapter.


I do have a TP Link manage switch, but don't have a clue to be able to configure VLAN with DD WRT.

The second option will not work, coz those kinds have access to the server room and it not secure, it just sit some where in the basement.

I will appreciate going the rout of manage switch and vlan but I don't have the knowledge to configure.
I appreciate if someone could guide me if they have the time and know how.

Thanks
e123enitan
DD-WRT Novice


Joined: 13 Mar 2017
Posts: 46

PostPosted: Wed Sep 06, 2017 13:34    Post subject: Reply with quote
DaveI wrote:
And there is one more low-tech way of dealing with this...You can Zip-Tie each end of the Ethernet cord. First Drill two small holes through the face plate of the ethernet port that has the SIP Adapter. Tightly wrap a zip-tie around the ethernet cord right by the RJ-45 connector and pass it through the holes you drilled in the face plate. Then pull the zip closed making sure there's no freefreeplay. Now the ethernet cord cannot be removed from the facplate. Reinstall the faceplate. Now you have to do the same thing on the SIP Adapter drilling two small holes in the platic case and wrapping the zip-tie around the ethernet cord on the end that plugs into the SIP Adapter...Then pass it through the two holes you drilled in the SIP adapter case (You'll need to remove the case to do this...Then pull everything tightly so the cord can't be removed from the SIP adapter. Then put the case on. This will stop them from being able to remove the cord from either the ethernet jack or the SIP adapter. Low-tech but it would work.
mgraben
DD-WRT Novice


Joined: 31 Oct 2016
Posts: 3

PostPosted: Wed Sep 06, 2017 18:42    Post subject: Reply with quote
If the router security method doesn't work and you don't want to drill into your equipment, there's another physical security method you could try. Go to Amazon and search for "RJ-45 cable locks". There are several devices that will lock your cable into the RJ-45 jack.
Goto page 1, 2  Next Display posts from previous:    Page 1 of 2
Post new topic   Reply to topic    DD-WRT Forum Index -> Marvell MVEBU based Hardware (WRT1900AC etc.) All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum