ER7412-M2 MAC Filtering - VPN Clients

ER7412-M2 MAC Filtering - VPN Clients

ER7412-M2 MAC Filtering - VPN Clients
ER7412-M2 MAC Filtering - VPN Clients
3 weeks ago
Tags: #VPN
Model: ER7412-M2  
Hardware Version: V1
Firmware Version: 1.0.1

Hello,

I have an L2TP client configured on my Omada. It works perfectly until I enable MAC filtering. Once MAC filtering is enabled, I lose connectivity. How can I prevent this from happening?

  0      
  0      
#1
Options
7 Reply
Re:ER7412-M2 MAC Filtering - VPN Clients
3 weeks ago

  @Colorful 

I am not sure I follow what you mean. Is there a typo in the description? 

And a diagram should be provided to explain your current setup. 

  1  
  1  
#2
Options
Re:ER7412-M2 MAC Filtering - VPN Clients
3 weeks ago

  @Clive_A 

What I mean is, I have an L2TP VPN server configured on my Omada that clients connect to. But when I configure MAC filtering and enable it immediately afterward, I can't reconnect to the VPN.

  0  
  0  
#3
Options
Re:ER7412-M2 MAC Filtering - VPN Clients
3 weeks ago

  @Colorful 

Colorful wrote

  @Clive_A 

What I mean is, I have an L2TP VPN server configured on my Omada that clients connect to. But when I configure MAC filtering and enable it immediately afterward, I can't reconnect to the VPN.

Any more details about the MAC filter?

This appears to be a problem with your config as described so far. 

  0  
  0  
#4
Options
Re:ER7412-M2 MAC Filtering - VPN Clients
3 weeks ago - last edited 3 weeks ago

 

@Clive_A 

 

When I enable MAC filtering, as I mentioned, it blocks my access to the VPN. In the “direction” tab, if I change it from “all” to LAN→WAN, I can then access the UTM, but I can’t connect via RDP.

  0  
  0  
#5
Options
Re:ER7412-M2 MAC Filtering - VPN Clients
3 weeks ago

  @Colorful 

 

MAC adresses from clients (pc, laptop, phone, whatever) are not maintained and carried over VPN - your mac address effectively becomes the MAC of the gateway as that is handling the connetion endpoint and NAT in<>out the WAN.

 

Therefore, if you have your MAC filtering set to "allow only those in the list" (which you do) instead of "block those in the list" your VPN connectivity will be blocked

Main: ER8411 x1, SG3428X x1, SG3452 x1, SG2428LP x1, SG3210 x1, SG2218P x1, SG2008P x3, ES208G x1, EAP650 x6 Remote: ER7206 v2 x1, ER605 v2 x3, SG2008P x2, EAP650 x2, ES205G x1 Controller: OC300
  0  
  0  
#6
Options
Re:ER7412-M2 MAC Filtering - VPN Clients
3 weeks ago

  @GRL 

Yes, that’s correct — the MAC addresses are not passed through the VPN. The gateway address is added to the list, so how can I fix the lack of connectivity to the VPN?

  0  
  0  
#7
Options
Re:ER7412-M2 MAC Filtering - VPN Clients
3 weeks ago

Hi  @Clive_A  do you have any suggestions on what can be done?

  0  
  0  
#8
Options