05-09-2022 02:00 PM
Dear Experts,
Can anyone teach me on how to manually config IP-MAC address on Firepower 2110?
I am using DHCP server from the Firepower for the guest network, but I would like to make one of device to be static.
Is it possible to configure manual binding? or Should I create another pool for that device and only 1 device can have that?
Correct me if I'm wrong.
I appreciate your reply.
05-09-2022 02:14 PM - edited 05-09-2022 11:41 PM
@eeebbunee you wouldn't create a IP/MAC binding on the FTD. You would create a DHCP reservation on your DHCP server.
On the FTD whatever IP address you assign the guest device via DHCP, you can create a host network object and reference in the ACP to permit/deny accordingly.
Ideally you'd integrate the FTD with ISE or ISE-PIC which would authenticate and authorise the users and dynamically send the IP bindings to the FTD.
05-09-2022 02:47 PM
Hello Rob,
Thanks for the response!
I'm not familiar to configure firepower rules, can you please provide more detail example for me?
When you said, create a host object and make a rule with that, host object can be created with network or text.
Is it meaning 'Text object'?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide