DHCP reservation
Hello,
I've got a Fortigate 30E Firewall and I need to create some reservations on one of my VLANS. The idea is to use DHCP reservations as a sort of ACL so only hosts with known MAC addresses can get access to this VLAN.
Previously I was using watchguard and I could set DHCP range to for exapmle: 192.168.1.200 - 192.168.1.200 and make reservations up to 192.168.1.254.
In FortiOS I can't do it this way and the IP range of DHCP has to be exactly the same as number of reserved addresses, it creates some issues, because in my network it looks like this:
192.168.1.129/25
192.168.1.130-140 - warehouse workstations
192.168.1.141-150 - warehouse printers
192.168.1.151-160 - office workstations
192.168.1.161-170 - office printers
and so on
So, when I was adding for example an office workstation I could make a reservation for address 192.168.1.155 and I didn't have to block unused addresses. Now I can't split it nicely, but I have to make a stack of addresses with all connected devices like 192.168.130-160 and when I add an office printer I need to extend DHCP range to 192.168.161 and it's a little bit too messy for me.
I hope I didn't overcomplicate it and you get my point. My question is: do you have any ideas how I can keep the IP addressing structure of my network without leaving empty addresses in DHCP?
