Guide ยท Docks and laptops
MAC address pass-through: why your dock shows the laptop's MAC, not its own
Plug the same dock into two laptops and the network sees two different MAC addresses. Boot one laptop into Windows, then Linux, and it can happen again. Here is the firmware feature behind it, and how to tell which address is which.
Short answer: if a USB-C dock or Ethernet dongle reports a MAC address that does not match the sticker on the dock, the laptop's firmware is almost certainly overriding it. Dell calls the feature MAC Address Pass-Through, or MAC Address Override; Lenovo and HP ship the same thing under nearly the same name. The dock keeps its own hardware MAC, but the driver programs the laptop's system MAC over it every time the link comes up, so the network always sees the computer, not whichever adapter it happens to be plugged into today.
The address can differ between Windows and Linux on one machine because pass-through is a cooperation between firmware and the network driver: the firmware publishes a MAC, and the driver decides whether to use it. Windows corporate images ship the OEM dock driver with pass-through wired up, so they apply the firmware value out of the box. Linux applies it only when the in-tree r8152 driver recognises both the dock chipset and the firmware's ACPI method, which depends on kernel version. Same laptop, same dock, two operating systems, and the address you observe is set by whichever layer won.
What pass-through actually does
A docking Ethernet port is a separate network interface controller, usually a Realtek RTL8153 or an ASIX part, with its own IEEE-registered MAC address burned in at manufacture. Plug three docks into one laptop and, without pass-through, the network sees three different MAC addresses. Plug one dock into three laptops and it sees the same address three times.
Pass-through inverts that. The laptop's firmware stores a single MAC that belongs to the system. When a supported dock attaches and its driver loads, the driver reads that value and sets it as the dock interface's address, shadowing the burned-in one. The dock's real MAC still exists and is still printed on its label; it is just not what goes on the wire. Because the firmware holds the value, it also applies during PXE boot, before any operating system loads.
Why it exists
Anything that identifies a machine by MAC address breaks when that address is really a property of a swappable accessory:
- Network access control. 802.1X and MAC Authentication Bypass allow or deny a switch port based on the address behind it. A shared hot-desk dock would authenticate as itself, not as the person sitting there.
- DHCP reservations and DNS. A fixed lease keyed to a laptop stops working the moment that laptop borrows a different dock.
- Imaging and inventory. Microsoft Configuration Manager, PXE deployment, and asset databases track devices by MAC. Pass-through keeps that identifier stable across a dock refresh or a warranty swap.
The trade is that the address on the wire no longer tells you which physical adapter produced the frame.
Which address is which
Three different MAC addresses are in play for one docked laptop:
| Address | Where it comes from | What a lookup returns |
|---|---|---|
| Dock label MAC | The RTL8153 or ASIX controller's own registered address, printed on the dock. What you see with pass-through disabled or unsupported. | Realtek, ASIX, and so on: the chipset maker. |
| Laptop system MAC | The value the firmware publishes. What you see with pass-through active. | Dell or Lenovo: on that hardware the value comes from the laptop maker's own registered block, even though the physical port is Realtek. |
| Built-in NIC MAC | On models that still have an internal Ethernet port, some firmwares pass through that port's exact address instead of a separate system value. | Same laptop maker, usually adjacent in its range. |
None of these is spoofed. They are all real unicast addresses; pass-through only chooses which one to present. A vendor lookup on a Realtek-based dongle that comes back as Dell is the expected result of the feature working, not a sign of tampering.
A small number of configurations, older firmware in particular, present a locally administered pass-through address instead of one from the maker's block. You can tell from the second hex digit of the first byte: 2, 6, A, or E there means locally administered, and no vendor lookup will resolve it. See how MAC addresses are structured for the bit that carries this.
How to check what is set
In firmware. The setting lives in BIOS or UEFI setup, under system or network configuration. Common names and values:
- Dell:
MAC Address Pass-Through, withDisabled,Integrated NIC 1 MAC Address,System Unique MAC Address, orPassthrough MAC Address. Dell documents how to read the value itself in its note on determining the pass-through MAC address. - Lenovo:
MAC address Pass Through, covered in Lenovo's support article for its USB docking solutions. - HP: an equivalent option, usually labelled
MAC Address Pass Through.
On Windows. Run getmac /v /fo list and compare the dock adapter's address with the dock's label. In Device Manager, open the dock's network adapter (typically "Realtek USB GbE Family Controller"), then Advanced, and look for a MAC Address Pass Through or Network Address property. Dell's overview of the feature notes the requirement that trips people up most: the OEM dock network driver has to be installed for the firmware setting to reach the OS at all.
On Linux. ip link show prints the current address per interface. To see whether the kernel applied a pass-through value, read the driver's log:
dmesg | grep -i r8152
journalctl -k | grep -iE 'r8152|pass.?thru|AUXMAC'
A line mentioning a pass-through or AUXMAC address means the kernel read it from the firmware's ACPI \_SB.AMAC method, which returns the address in the form _AUXMAC_#AABBCCDDEEFF#. Support arrived with the Dell TB15 and WD15 docks (RTL8153-AD) and was extended to later chips; the mechanism is described in the kernel's r8152 pass-through patch. If your kernel predates support for your dock, or the dock is not on the recognised list, Linux uses the dongle's own MAC and you get a different address from Windows.
systemd adds one more twist. Its default MACAddressPolicy=persistent can assign a stable hashed address to an interface that would otherwise have a random one. That is a separate mechanism from firmware pass-through, but it produces the same "why is this not the label MAC" question. udevadm test-builtin net_setup_link /sys/class/net/IFACE shows what the policy decided for a given interface.
What it means in practice
- Do not key DHCP reservations or NAC rules to a dock's label MAC when pass-through is on. Use the system MAC, and confirm every OS the machine boots presents the same one.
- Expect a dual-boot machine to have two Ethernet MACs unless pass-through is supported and enabled on both sides. Disabling it in firmware makes both operating systems fall back to the dongle's own address.
- A Realtek dongle that looks up as Dell or Lenovo is normal. The vendor you get back reflects who owns the address, which under pass-through is the laptop maker.
- The dock's real MAC is still on its label and is still what a different, non-supporting host would see through it.
To check any of the three addresses above, run it through the lookup: it reports the registered vendor and whether the address is locally administered. For the universal/local bit itself, see how MAC addresses are structured; for the other common reason an address is not what you expected, see MAC address randomization. To read the address on any OS by hand, find your MAC address walks through the commands.
More guides