Community discussions

MikroTik App
 
engineertote
Member Candidate
Member Candidate
Topic Author
Posts: 177
Joined: Tue May 19, 2009 1:36 pm

Script to Hide MT interface MAC address

Sun Dec 18, 2011 11:11 am

Hi

i need a script to hide the MAC address of interface on the local side so the client will not see what is the MAC address of my Mikrotik as some attackers using sniper programs to know the MT Mac address and do virtual server on them PCs to attack the users .

Regards
Ahmed
 
mmmigoro
newbie
Posts: 39
Joined: Mon Feb 14, 2011 3:48 pm
Location: PRAHOVA, Romania

Re: Script to Hide MT interface MAC address

Sun Dec 18, 2011 2:04 pm

There is no such script as MAC address is an essential component of layer2 functionality. If you hide MT's MAC address then you will lose connectivity with MT.

The best you can do is to implement in front of MT a layer2+ switch (such as Zyxel ES-3124) with ARP guard to filter out intruders. Be aware that you need to activate DHCP snooping at least one or two days before running ARP guard otherwise you risk cutting off legitimate customers.

Other thing you can do is to change MT's MAC address periodically, there's even a scrip for this, but this offers you no protection in front of an attacker.
 
JorgeAmaral
Trainer
Trainer
Posts: 199
Joined: Wed Mar 04, 2009 11:53 pm
Location: /ip route add type=blackhole

Re: Script to Hide MT interface MAC address

Tue Dec 20, 2011 4:55 am

Read this excellent presentation done by Wardner Maia

Layer 2 Security - Attacks and Countermeasures using MikroTik RouterOS
http://mum.mikrotik.com/presentations/PL10/maia.pdf

I think that you can grab some ideas from there.
 
engineertote
Member Candidate
Member Candidate
Topic Author
Posts: 177
Joined: Tue May 19, 2009 1:36 pm

Re: Script to Hide MT interface MAC address

Wed Dec 21, 2011 10:27 am

Thanks

Read this excellent presentation done by Wardner Maia

Layer 2 Security - Attacks and Countermeasures using MikroTik RouterOS
http://mum.mikrotik.com/presentations/PL10/maia.pdf

I think that you can grab some ideas from there.

Who is online

Users browsing this forum: No registered users and 4 guests