Home
Help
Search
Login
Register
OPNsense Forum
»
Archive
»
22.1 Legacy Series
»
how to block unknown IPs on LAN?
« previous
next »
Print
Pages: [
1
]
Author
Topic: how to block unknown IPs on LAN? (Read 1184 times)
gnomegemini
Newbie
Posts: 1
Karma: 0
how to block unknown IPs on LAN?
«
on:
May 05, 2022, 07:44:34 am »
Hey there,
I just want to block any client, now known to the DHCPv4 service. So I add a machine to DHCPv4 with it's MAC and this is OK. But I want block all other machines not listed in DHCPv4 services.
Do I really need to add a "block all but a,b,c,d not" rule and add another IP everytime or is there any way to "combine" it like "block all except the ones with DHCPv4 lease"?
Any help is very much appreciated.
Kind regards
Stefan
Logged
fabian
Hero Member
Posts: 2769
Karma: 200
OPNsense Contributor (Language, VPN, Proxy, etc.)
Re: how to block unknown IPs on LAN?
«
Reply #1 on:
May 05, 2022, 05:53:41 pm »
Static ARP option is likely the best to go.
Logged
EdwinKM
Full Member
Posts: 155
Karma: 5
Re: how to block unknown IPs on LAN?
«
Reply #2 on:
May 05, 2022, 09:46:47 pm »
not tested. But this is not intended as security. If a person set a static IP (in the range) it will probably just work.
Logged
zerwes
Full Member
Posts: 125
Karma: 8
Re: how to block unknown IPs on LAN?
«
Reply #3 on:
May 06, 2022, 09:29:46 am »
In fact this is rather a LAN security option (dot1x) and not the job of the firewall, as it would be the best to block access to the LAN for unknown clients first, stopping them on the firewall level is in fact to late and IMHO not really doable ... you can try to read the lease file into a alias ant then just allow traffic from this alias but this assumes that all clients release their lease and you have a short lease time ... I would not go for this.
If your switche(s) are dot1x capable, opnsense has a freeradius plugin (I never used it, I prefer to have such services outside of the firewall)
If you implement dot1x I would not just go by a MAC filter, as MACs can easily be changed, you should go at least for eap tls ... but that is beyond the scope of this.
Logged
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
Archive
»
22.1 Legacy Series
»
how to block unknown IPs on LAN?