Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    DHCP LEASES some mac address that are not allowed is shown in the dhcp leases

    Scheduled Pinned Locked Moved DHCP and DNS
    8 Posts 4 Posters 974 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • I
      invoker
      last edited by

      hello sir,

      some of the mac address that is not allowed in captive portal was shown in the the dhcp leases / it was active

      johnpozJ S GertjanG 3 Replies Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator @invoker
        last edited by

        @invoker kind of hard to talk to the captive portal in the first place, if the device can't get an IP.. So kind of requirement for device to get an IP from dhcp.

        If you want to block some device from getting an IP from dhcp, you should set that up in the dhcp server or your wifi network from macs connecting in the first place.

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.8, 24.11

        I 1 Reply Last reply Reply Quote 1
        • S
          SteveITS Galactic Empire @invoker
          last edited by

          @invoker In the DHCP Server config, see the "Deny unknown clients" choice.

          Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
          When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
          Upvote ๐Ÿ‘ helpful posts!

          I 1 Reply Last reply Reply Quote 1
          • I
            invoker @johnpoz
            last edited by

            @johnpoz i already filtered MAC address in my captive portal the one that i filtered is the one that i allow to connect to the dhcp or to have internet but suddenly in the dhcp leases there are some MAC address that is showing but not in the list of filtered MAC address that i allow.

            1 Reply Last reply Reply Quote 0
            • I
              invoker @SteveITS
              last edited by

              @SteveITS thank you sir

              1 Reply Last reply Reply Quote 0
              • GertjanG
                Gertjan @invoker
                last edited by

                @invoker said in DHCP LEASES some mac address that are not allowed is shown in the dhcp leases:

                some of the mac address that is not allowed in captive portal was shown in the the dhcp leases / it was active

                As said by @SteveITS

                In the DHCP Server config, see the "Deny unknown clients" choice.8

                I'l detailed this one yesterday :

                Maybe you do need this.

                But using a captive portal, a network for unknown devices and non trusted devices, when you accept only known devices .... that the world upside down.

                @invoker said in DHCP LEASES some mac address that are not allowed is shown in the dhcp leases:

                @johnpoz i already filtered MAC address in my captive portal the one that i filtered is the one that i allow to connect to the dhcp or to have internet but suddenly in the dhcp leases there are some MAC address that is showing but not in the list of filtered MAC address that i allow.

                MAC blocking isn't actually blocking MAC's (like : no traffic what so ever) when using that functionality on the captive portal.
                Examples :

                4f085933-285b-457b-a373-ebc227851b9b-image.png

                The first entry : it's like the captive portal isn't there for the 00:11:22:33:44:55 user. GUI Interface rules still apply, though.
                Second entry : the user did get an DHCP lease, IP, gateway, etc. He even sees the login page, with a message : "You are blocked" (something like that).

                This : MAC Address Control says "Always deny traffic from this MAC address" and that's not really what happens : the device and the portal are exchanging traffic, as you will see the login page, and the blocked message. Other traffic, like visiting other (Internet) web pages, isn't possible.

                No "help me" PM's please. Use the forum, the community will thank you.
                Edit : and where are the logs ??

                johnpozJ 1 Reply Last reply Reply Quote 0
                • johnpozJ
                  johnpoz LAYER 8 Global Moderator @Gertjan
                  last edited by

                  @Gertjan said in DHCP LEASES some mac address that are not allowed is shown in the dhcp leases:

                  when you accept only known devices .... that the world upside down.

                  Yeah kind of defeats the whole point of a captive portal if you ask me. You you only allow known devices to connection - what is the point of captive portal then?

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.8, 24.11

                  GertjanG 1 Reply Last reply Reply Quote 0
                  • GertjanG
                    Gertjan @johnpoz
                    last edited by

                    @johnpoz said in DHCP LEASES some mac address that are not allowed is shown in the dhcp leases:

                    You you only allow known devices to connection - what is the point of captive portal then?

                    It boils down to "what is my concept of networking", and then "yours", and then, after some extrapolation, you'll find a lot of so called definitions of one and the same thing out there.

                    pfSense might even be at fault here, as it might induce this impression that every possible collection of selected options and settings can create a workable or useful solution for someone ๐Ÿ˜Š

                    I guess we'll reach that point in the future : invent something (whatever), and some one else has already tried it. This forum has already a nice collection of them.

                    No "help me" PM's please. Use the forum, the community will thank you.
                    Edit : and where are the logs ??

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.