Sorry if this is a dumb question, but did you make sure the customer didn't plug their WAN link into a LAN port? On Wed, Sep 16, 2026, 6:19 PM Brandon Martin via NANOG < nanog@lists.nanog.org> wrote:
On 9/16/26 18:08, Majdi S. Abbas wrote:
If the access technology you're using supports it, some form of mac locking/filtering your access customers is the usual way SPs handle unwanted traffic.
But how does one determine what MAC address to lock to? You can't lock to the first MAC you see. That could be something random on their LAN. You can't even lock to the first thing you see that sends a DHCP request for the same reason.
The only thing I can think of that would be reasonably automated is trialing extremely short aging times and lease expiry times until you're "reasonably confident" that the "real" router has actually shown up then locking to that. That seems...problematic. Also hard to programmatically define especially in a way that an access layer can handle.
Do people just manually purge whatever they see during initial install until they're sure that the "real router" is there then statically lock the port to that MAC? Jeesh, that's messy, but I guess it's functional.
I can keep unwanted traffic from being a network operational issue. The issue is separating the unwanted from the wanted. -- Brandon Martin Mothic Technologies 317-565-1357 x7000 _______________________________________________ NANOG mailing list
https://lists.nanog.org/archives/list/nanog@lists.nanog.org/message/ON4QCLSD...