Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

Any way to delete a device that picked up a DHCP Leased Address?

Hello All, Just a question, as I poked around for awhile and couldn' t find a quick way to do this. Have an unknown device plugged into a switch somewhere that has picked up a DHCP Address. Is there a way to ban / clear a particular device from the DHCP List of leases? Thanks.....Scott
3 REPLIES 3
rwpatterson
Valued Contributor III

What is the ultimate goal? If it' s to make sure this device gets no access, set up a DHCP-MAC binding, and then use policies to deny it access. Once the unit has been bound, it can' t get out using that address or any other.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
ede_pfau
SuperUser
SuperUser

For ease of use I usually bind rogue MAC addresses to otherwise unused and non-routed IP addresses like 192.168.253.253 or 9.8.7.6. As this network isn' t used anywhere in the config the default (implicit) firewall DENY policy will catch it eventually. Less effort to set up and remove later. Don' t forget to manually kill the existing lease - some culprits set up keepalive traffic to permanently renew the same (valid) IP address.
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
emnoc
Esteemed Contributor III

Same here, but I like to use the experimental range. 192.0.1.0/24 or 1.1.1.0/24 none of these networks are routed on the internet.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors