cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
468
Views
0
Helpful
4
Replies

restrict dhcp by hardware?

jessica jestol
Level 1
Level 1

In linux, it's possible to create a class where you can match hardware (in my case the mac prefix of the first six characters) that will only allow dhcp if the mac address of the requester starts with those six characters. Is there any way to do this with cisco IOS? I'm talking about more than 50 clients so mac reservation isn't an option and no server on site so 802.1x isn't an option either. Basically, it would be a simple but effective way of saying, nothing connects here but this specific hardware. Yes, I know mac spoofing is easy but I'd like some additional protection beyond the port security option.

4 Replies 4

Dennis Mink
VIP Alumni
VIP Alumni

You can't exclude a MAC address directly  on the IOS based DHCP server.

What you can do is  to give the MAC address a manual binding on an invalid subnet - thus black holing the client

Please remember to rate useful posts, by clicking on the stars below.

I was thinking more only allow mac addresses that start with C8:08:E9.

Hi,

I think it is possible with Vendor Class ID:

 

 

https://**bleep**.technology/configure-cisco-ios-dhcp-to-use-vendor-class-ids

 

Actually, correct URL is "**bleep**.technology" but I don't know why it is converting to **bleep**.

 

I attached a file with correct URL. Please check. I think this is an issue with Cisco Support form.

 

 

Regards,

Deepak Kumar

Regards,
Deepak Kumar,
Don't forget to vote and accept the solution if this comment will help you!

hahaha. That's funny. Thanks. I was thinking this might work as well. I'm reading up on it now.

Review Cisco Networking for a $25 gift card