deny static ip

Malte Starostik lists at malte.homeip.net
Sat Sep 15 13:52:49 UTC 2012


Hello networkgroup,

Am Samstag, 15. September 2012, 18:25:35 schrieb networkgroup at bbnl.co.in:
> Some of the clients under our network is using static in same pool
> which we have create in dhcp.So we are facing ip collision  every time
> .Is their any way to block static ips under same network?

dhcpd can't do this for you and it's not supposed to.  As Dwayne said, you can 
at least try to avoid handing out IPs used by such "rogue" clients - IIRC they 
only need to reply to ARP requests, not ICMP echo but IMBW.

The real fix would be to leverage your network gear for this.  e.g. some 
switches can be set to initially only allow DHCP requests and after address 
assignment block everything on the port that doesn't have the MAC/IP combo as 
was blessed by the DHCP server.  Still allows for spoofing though.  If you want 
to really tighten up your net, you'd need to go for 802.1x.

None of that is dhcpd's business though :)

Regards,
Malte


More information about the dhcp-users mailing list