Zum Inhalt springen

OUI database

The first bytes of a MAC address are assigned by the IEEE to the company that made the network interface. The OUI database is Taranac’s local copy of those assignments. It is where the Manufacturer of every endpoint comes from, and it answers without any network access, for every device, including one that has never said a word about itself.

It is found under NAC → Discovery Sources → OUI Database.

TermWhat it means
OUI / prefixThe part of a MAC address the IEEE assigned to one organisation: 24, 28 or 36 bits long, depending on the registry.
RegistryOne of the five lists the IEEE publishes: MA-L, MA-M, MA-S, IAB and CID.
ManufacturerThe organisation name for the longest prefix that matches a MAC, plus a short display name.
Randomised MACA locally administered address a phone or laptop invents per network. No manufacturer can be read from it.
RegistryPrefix lengthWhat it is
MA-L (large)24 bits (XX:XX:XX)The classic OUI: about 16 million addresses per block. Most of the table.
MA-M (medium)28 bits (XX:XX:XX:X)About a million addresses per block.
MA-S (small)36 bits (XX:XX:XX:XX:X)About 4,000 addresses per block.
IAB36 bitsThe older form of the small block.
CID24 bitsCompany IDs, for organisations that need an identifier and do not build hardware under it.

All five are loaded, because the finer blocks are carved out of 24-bit blocks the IEEE registers to itself. A table holding only MA-L answers IEEE Registration Authority for every device from a small manufacturer. That is not a manufacturer. The makers behind these blocks are largely sensor, controller and embedded-device firms, precisely the devices that cannot do 802.1X and are admitted by MAB.

A lookup tries the longest prefix first: 36 bits, then 28, then 24. A MAC such as 70:B3:D5:CB:1A:2B sits inside both IEEE’s own 24-bit block and a manufacturer’s 36-bit block. Longest first finds the manufacturer:

70:B3:D5 (MA-L, 24 bits) IEEE Registration Authority
70:B3:D5:CB:1 (MA-S, 36 bits) RADAR ← the answer
  • First start. Taranac downloads all five registries from standards-oui.ieee.org. If none can be fetched, it loads the bundled snapshot shipped in the image, which covers all five registries (about 58,000 prefixes). An offline installation therefore names manufacturers from the start. The snapshot is loaded only into an empty table. It never overwrites data a sync has already brought.
  • Weekly update. Every Sunday at 02:00 the leader downloads the registries again, when Auto-update is on (the nac.oui_auto_update setting under NAC Settings, on by default). If only some registries answer, the update goes ahead with those, and the others are tried again the next week. If none answer, nothing changes until the next run.
  • Sync Now on the page runs the same update on demand. It takes 30 to 60 seconds, reports how many prefixes were added and updated, and fails cleanly, leaving the table as it was, if the IEEE is unreachable.

An update adds new prefixes and updates changed names. It does not delete a prefix the IEEE has withdrawn, so a rule written against an old name keeps matching.

On an installation with no route to the internet, the table stays at the snapshot of the release it was first installed with.

The OUI Database page: Total manufacturers, Last updated and Auto-update cards, and the Quick MAC Lookup answering DC:A6 → Raspberry Pi Trading for the MAC DC:A6:32:11:22

  • Total manufacturers: how many prefixes the table holds.
  • Last updated: when a sync last changed it.
  • Auto-update: whether the weekly sync is on.
  • Quick MAC Lookup: type a MAC (AA:BB:CC:DD:EE:FF) or a prefix (AA:BB:CC) and read the manufacturer from the local table, with the matching prefix.
  • The table: OUI Prefix, Manufacturer, Short Name. The search box matches by hex prefix when you type hex (DC:A6, DCA632), and by name otherwise.

Viewing the page needs the Endpoints view permission. Sync Now needs Endpoints edit.

The endpoint’s Manufacturer. When an endpoint is created, its Manufacturer (vendor) and OUI prefix (oui_prefix, always the first three bytes of the MAC) are filled from the table. The name is stored as plain text, not as a link to the table. An IEEE rename does not silently change what your existing endpoints and rules say. Where a list or journal shows a manufacturer for a MAC that is not stored with one, such as the DHCP Probe’s messages, it is looked up when displayed, so it follows the latest sync.

Classification. Two endpoint group rule types read it. vendor_name matches the manufacturer. If the stored endpoint has none, it is looked up from the MAC. oui_prefix matches the first three bytes. Both rule forms have a picker over this table, so you can find a manufacturer and see how many prefixes it owns. A vendor_name rule for a name the table does not hold yet is saved anyway, and starts matching once a sync brings that manufacturer.

Device Profiling. The Manufacturer prefix (OUI) signal lets a profiling rule conclude a manufacturer, or more, from the first three bytes. It is present for every device with a globally assigned MAC. See Device profiling.

Web Probe. A source can send vendor and oui_prefix to your script, and an endpoint a Web Probe creates is given its manufacturer at once.

You want to match…Use
Everything a manufacturer makes, whatever block it came fromvendor_name
One specific 24-bit block, such as one product line that has its own OUIoui_prefix
A device from a 28- or 36-bit blockvendor_name: its first three bytes belong to the IEEE’s shared block, not to the maker
A randomised MACNeither can work. Use a host name, a certificate, a directory rule or a profile.
ItemValue
MenuNAC → Discovery Sources → OUI Database
RegistriesMA-L, MA-M, MA-S, IAB, CID from standards-oui.ieee.org
MatchingLongest prefix first: 36, 28, then 24 bits
OfflineBundled snapshot of all five registries, loaded into an empty table when the IEEE cannot be reached
ScheduleWeekly, Sunday 02:00, leader only (job OUI Database Update)
Settingnac.oui_auto_update (default true)
PermissionsEndpoints: View (page, lookup); Edit (Sync Now)