--- title: "Activate MAC filters - IT Security" slug: "it-security-hardening-activate-mac-filters-en" updated: 2024-07-19T07:03:36Z published: 2024-07-19T07:03:36Z canonical: "docs.insys-icom.com/it-security-hardening-activate-mac-filters-en" --- > ## Documentation Index > Fetch the complete documentation index at: https://docs.insys-icom.com/llms.txt > Use this file to discover all available pages before exploring further. # Activate MAC filters - IT Security The MAC filters block the IP connections to other devices in the Ethernet following the white list principle, i.e. all connections are blocked unless they are explicitly permitted here. MAC filter rules apply to both, IPv4 and IPv6 traffic. > [!NOTE] > Please note! > > Default settings contain one MAC filter rule already that permits data traffic with the MAC address FF:FF:FF:FF:FF:FF to all IP networks of the router. The MAC address FF:FF:FF:FF:FF:FF is the broadcast address for ARP (Address Resolution Protocol). Without this rule and activated MAC filters, no ARP requests would be possible for example that are used by the router to determine the assignment between IP and MAC address of the network devices. 1. Click in the ![lan](https://docs.insys-icom.de/assets/icons/lan.png) *Network* → *Firewall / NAT* menu in the *Firewall* section on ![pencil](https://docs.insys-icom.de/assets/icons/pencil.png) and check the checkbox *MAC filter activated*. 2. Click on **SUBMIT** . 3. Click in the *MAC filter* section on ![plus](https://docs.insys-icom.de/assets/icons/plus.png) to add a new filter rule: - Select the *Interface* for which the device with the specified MAC address is permitted; If no interface is selected, it is permitted for all interfaces. - Enter the *MAC address* of the device, for which the selected interface is permitted; If no MAC address is specified, all devices independent of their MAC address are permitted for this interface. 4. Click on **SUBMIT** . 5. Click on **ACTIVATE PROFILE** **![cog white](https://docs.insys-icom.de/assets/icons/cog_white.png)** . > [!NOTE] > Create a filter rule for each device in the network! > > Filter rules in which neither an interface nor a MAC address are specified will be ignored. > [!NOTE] > Please note! > > It is recommended to check all existing filter rules for their necessity and deactivate them, if applicable. > [!CAUTION] > Take care not to lock yourself out! > > If the connection of the computer in the configuration network that is used to access the web interface of the router is not permitted explicitly in the MAC filter, no further local connection can be made!