Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Refuse RFC1918 offers on DHCP WAN

    Scheduled Pinned Locked Moved DHCP and DNS
    7 Posts 3 Posters 1.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • luckman212L Offline
      luckman212 LAYER 8
      last edited by

      On 2.3.x, if I want to reject DHCP offers from 192.168.100.0/24 how should that be entered?
      When I try to enter it like this, it gets rejected for syntax:


      1 Reply Last reply Reply Quote 0
      • jimpJ Offline
        jimp Rebel Alliance Developer Netgate
        last edited by

        I split this off since the other post was 3 years old and this is a different question.

        You don't need to reject the entire subnet, just the DHCP server in that subnet, which is probably your modem at 192.168.100.1

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • luckman212L Offline
          luckman212 LAYER 8
          last edited by

          Thanks Jim.  Ok, I know in a past version (maybe 2.2 or 2.1) it did accept a subnet there.  If it only accepts individual IPs now, the wording beneath the field should remove the "…place the IP address or subnet of the DHCP server…" since that is a bit confusing.

          1 Reply Last reply Reply Quote 0
          • johnpozJ Offline
            johnpoz LAYER 8 Global Moderator
            last edited by

            So you can not use subnet?  What if your isp has a bunch of dhcp servers on the same subnet you want to block and only accept IP from different set of dhcp servers?

            I agree with luckman212 if you can not use subnet in some form of /cidr or whatever then the "or subnet" should prob be removed from the description ;)
            "

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 25.07.1 | Lab VMs 2.8.1, 25.07.1

            1 Reply Last reply Reply Quote 0
            • jimpJ Offline
              jimp Rebel Alliance Developer Netgate
              last edited by

              The text probably needs to be corrected. It may have allowed the entry before but I don't think it worked. According to the man page it only takes an IP address.

              reject ip-address;
                  The reject statement causes the DHCP client to reject offers from
                  servers who use the specified address as a server identifier.
                  This can be used to avoid being configured by rogue or misconfig-
                  ured DHCP servers, although it should be a last resort - better
                  to track down the bad DHCP server and fix it.

              Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

              Need help fast? Netgate Global Support!

              Do not Chat/PM for help!

              1 Reply Last reply Reply Quote 0
              • jimpJ Offline
                jimp Rebel Alliance Developer Netgate
                last edited by

                I pushed a change to fix the description so that it only lists IP address, not subnet.

                Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                Need help fast? Netgate Global Support!

                Do not Chat/PM for help!

                1 Reply Last reply Reply Quote 0
                • luckman212L Offline
                  luckman212 LAYER 8
                  last edited by

                  Thanks!  I was about to submit my own PR but as I was about to push it, I noticed that you had already changed the text ;)

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.