Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Marcos_FDS1012
Contributor

Release DHCP only when the machine's MAC has been fixed together

I need to make it so that when a machine plugs a network cable into my network it can't get an IP via DHCP, but when I register the machine's MAC it can use my NETWORK, how could I do that?

2 Solutions
funkylicious
SuperUser
SuperUser

what acts as a dhcp server in your network ?

is it the FortiGate or another device ?

"jack of all trades, master of none"

View solution in original post

"jack of all trades, master of none"
funkylicious

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-control-DHCP-user-via-MAC-address/t... 

  • Action for 'Unknown MAC Address' as 'Assign IP' or 'Block IP' can be set (recommendation will be to set the action as block IP).

this will limit the assignment of DHCP to the devices. use with caution tho, it can deny DHCP to any devices that should be permitted if they are not reserved ahead of time.

 

anothet thing, https://docs.fortinet.com/document/fortigate/7.2.0/new-features/59285/add-vci-pattern-matching-as-a-... to look for patterns in the dhcp request 

 

another thing if your network supports, would be dot1x ( 802.1x ) with port-security 

"jack of all trades, master of none"

View solution in original post

"jack of all trades, master of none"
3 REPLIES 3
funkylicious
SuperUser
SuperUser

what acts as a dhcp server in your network ?

is it the FortiGate or another device ?

"jack of all trades, master of none"
"jack of all trades, master of none"
Marcos_FDS1012
Contributor

And fortegate that it's my DHCP

funkylicious

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-control-DHCP-user-via-MAC-address/t... 

  • Action for 'Unknown MAC Address' as 'Assign IP' or 'Block IP' can be set (recommendation will be to set the action as block IP).

this will limit the assignment of DHCP to the devices. use with caution tho, it can deny DHCP to any devices that should be permitted if they are not reserved ahead of time.

 

anothet thing, https://docs.fortinet.com/document/fortigate/7.2.0/new-features/59285/add-vci-pattern-matching-as-a-... to look for patterns in the dhcp request 

 

another thing if your network supports, would be dot1x ( 802.1x ) with port-security 

"jack of all trades, master of none"
"jack of all trades, master of none"
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors