Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    DHCP settings if all devices of the VLAN are static mapping

    Scheduled Pinned Locked Moved DHCP and DNS
    8 Posts 3 Posters 458 Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R Offline
      richardsago
      last edited by

      Good day. What is the DHCP settings for a VLAN if the only allowed devices are those devices whose MAC Addresses are set in static mapping?

      In this example only these devices should be allowed to connect to this VLAN:
      182f851f-3f86-4f99-9ed4-e64bfaee9dd3-image.png

      The DHCP is enabled. Will the static mapping of the IP Addresses of the devices be implemented if this is disabled?
      752bb356-17ec-4f43-b5ad-a36f1f3b9ee4-image.png

      How to prevent the one device that will be given 172.16.111.254 IP Address by the DHCP Server? Thank you in advance.
      3fa13e56-1e2e-4b12-888d-080f10576044-image.png

      GertjanG 1 Reply Last reply Reply Quote 0
      • GertjanG Offline
        Gertjan @richardsago
        last edited by Gertjan

        @richardsago said in DHCP settings if all devices of the VLAN are static mapping:

        The DHCP is enabled. Will the static mapping of the IP Addresses of the devices be implemented if this is disabled?

        Easy answer : ask the admin, as he has some work to do.

        This :

        1e767c98-8c95-4d82-84a8-d8fed00ba503-image.png

        means that one(1) device who hasn't a static lease set up upfront, will receive a dynamic DHCP lease.
        The next device that asks a dynamic lease - and hasn't a static lease set up, will receive a NAK, or 'go away' and will fall back to a 169.a.b.c non routable IPv4.
        But maybe this is what you want.

        So : make an inventory of all your known devices (even the ones you don't know about) and make a list like this :

        0fbf67b1-f2d3-4ba6-9d1a-a06a879d9a58-image.png

        and from that moment, all your 'known' devices will get 'their' 'static' IPv4 - for live.
        Bonus : you control the host names, so no more

        b8:94:e7:4a:d7:cc Xiaomi Communications Co Ltd
        

        but :

        172.16.111.100 My-Sisters-F-Clone-Droid-phone
        

        where "My-Sisters-F-Clone-Droid-phone" is the host name.

        I presume you've already done this ^^ but you didn't told about it.

        Btw : ISC ?
        Consider :

        960f9609-a2da-4249-a73d-e19811fc0274-image.png

        as it (pfSense's kea implementation) has reached the "good enough for me" stage.

        No "help me" PM's please. Use the forum, the community will thank you.

        1 Reply Last reply Reply Quote 0
        • R Offline
          richardsago
          last edited by

          Thank you @Gertjan for the reply. If the "Enable DHCP server on VLAN10 interface" is turned off and only the authorized devices' MAC Addresses are added in the DHCP Static Mappings and "Allow known clients from only this interface" was chosen in the "Deny Unknown Clients", will the authorized devices get the IP Address from the static mappings? Or the authorized devices will not receive any IP Address because the DHCP is turned off on this VLAN?

          S 1 Reply Last reply Reply Quote 0
          • S Offline
            SteveITS Rebel Alliance @richardsago
            last edited by

            @richardsago no IPs will be handed out if DHCP Serverbis not running.

            Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
            When upgrading, allow 10-15 minutes to reboot, or more depending on packages, CPU, and/or disk speed.
            Upvote 👍 helpful posts!

            R 1 Reply Last reply Reply Quote 0
            • R Offline
              richardsago @SteveITS
              last edited by richardsago

              Thank you @SteveITS for the reply. If the "Enable DHCP server on VLAN10 interface" is turned on and only the authorized devices' MAC Addresses are added in the DHCP Static Mappings and "Allow known clients from only this interface" was chosen in the "Deny Unknown Clients", is there a way for the DHCP Address Pool Range to be set to blank so that only the authorized devices in the static mapping can be given IP Addresses?

              edited to add this screenshot:
              32d1c1e0-de20-4cb7-be18-054b630c288e-image.png

              GertjanG 1 Reply Last reply Reply Quote 0
              • GertjanG Offline
                Gertjan @richardsago
                last edited by Gertjan

                @richardsago said in DHCP settings if all devices of the VLAN are static mapping:

                Thank you @SteveITS for the reply. If the "Enable DHCP server on VLAN10 interface" is turned on and only the authorized devices' MAC Addresses are added in the DHCP Static Mappings and "Allow known clients from only this interface" was chosen in the "Deny Unknown Clients", is there a way for the DHCP Address Pool Range to be set to blank so that only the authorized devices in the static mapping can be given IP Addresses?

                Although this is valid for kea (can't remember ISC anymore ^^ ) :

                03f22187-5b88-4a19-99e2-adeaffb10427-image.png

                what I make of it : only static MAC DHCP devices will get a device.
                A device not present in that list (bottom of the DHCP server page) will not receive a lease.
                Easy to test : just keep an eye on Status > DHCP Leases if dynamic leases where allocated.

                The fact that you have a minimal DHCP pool present doesn't mean that it will be used.

                edit : and I presume ISC had the same functionality.

                No "help me" PM's please. Use the forum, the community will thank you.

                R 1 Reply Last reply Reply Quote 1
                • R Offline
                  richardsago @Gertjan
                  last edited by

                  Thank you @Gertjan for the reply. I could be wrong but I remember our pfsense 2.1 of many versions ago does not allow a blank value in the Address Pool Range so it has a single IP address in the pool range. And what would happen is an unregistered device will receive this IP address and will be listed in the DHCP Leases. I will test in the next available time.

                  S 1 Reply Last reply Reply Quote 0
                  • S Offline
                    SteveITS Rebel Alliance @richardsago
                    last edited by

                    @richardsago that’s a long time ago… Anyway that is the point of “Deny unknown clients” and yes it does work.

                    Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                    When upgrading, allow 10-15 minutes to reboot, or more depending on packages, CPU, and/or disk speed.
                    Upvote 👍 helpful posts!

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.