This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

When do I use MAC Host / IP Host

Hello,

can someone explain to me when I should use a MAC host and / or an IP host, when does that make sense.

Or do I even have to create both, although in my other thread it was already discussed why there is not a finished client object.

It is absolutely not understandable for me what it is supposed to create a MAC host or IP host separately.

Well, that would be worth an answer in my other thread.

Back again, when do I use a MAC host or IP host.

I absolutely do not understand this type, because a client basically has a MAC and IP, at least for my understanding when trying to work with rules.

Thanks and greetings



This thread was automatically locked due to age.
Parents
  • I never use MAC Lists in my life, as it is way to complicated to maintain all those devices. But from my point of view, i look at the bigger installations (more than 20 devices online). I do not want to keep up with the entire MAC List and maintain all new devices and delete the old ones etc. 

    MAC in firewall rules is a relic of a old time, using NAC to maintain a network. If you look at solutions on the market, using MAC to do this stuff, they can easily get messy, if looking at bigger networks. Of course for smaller networks or even home networks, this is not the case but even there: What do you do with guests, what do you do with a device, switching macs? it is always not easy to relay on such static measures. Also most customers could use a layer 3 switch and therefore MAC filtering will not work (because MAC gets replaced). 

    You can simply create a mac list with all your macs, place it in a firewall rule and block / allow the access. 

    XG Firewall really comes into play if you get a authentication method into place, which replace this entire "i create a object for the task". See: https://support.sophos.com/support/s/article/KB-000035643?language=en_US 

    • If MAC Binding is enabled and the MAC address is not entered in the MAC address List, Sophos Firewall will automatically bind the MAC address of the user’s device on their first login.

     

    If you use IP hosts in a firewall rule, you need to make sure, the same host gets the same IP all the time. Therefore you need to figure out, if you want to use the static IP leases of XG itself or you have a own DHCP server. Again, if you have a automatic authentication service, it will replace this method of static IP hosting and map a person (user) to a IP and you can use the person in a firewall rule. 

    __________________________________________________________________________________________________________________

  • ok, what options do I have to be able to set up the same use case in the manner of the SG firewall.

    I would like to build the type of IP and Mac binding. I also have microcontrollers that cannot log in.

    How do I deal with such clients?

Reply Children