11-03-2021 09:14 AM
Hi guys,
We're trying to do some actions to improve the security in our company. We'd like to establish a whitelist of MAC addresses, to do so, we want to use the "Filters" function of our DHCP server ; by adding only the MAC addresses we trust in the "Allow" filter and then activate this filter, we should be able to achieve this goal.
Now, we often have visitors coming on site who need to have a Guest Internet Access. It's already defined in our WLan controller and it's working well but we noticed that it's contacting our DHCP to establish the connection so if we activate the DHCP filter, our visitors won't be able to connect to our Guest Access anymore.
I'd like to know if we can change the setting of our WLan so it "ignores" the DHCP but still gets an IP address and internet access. Do you think it's achievable ?
Thanks,
Regards
Solved! Go to Solution.
11-03-2021 01:05 PM
DHCP filters will not increase security, rather they will bring lot of management problems. Also you need to keep in mind that MAC randomization is enabled on most of the devices now.
For your Guest network you need to check on your DHCP server if you have an option to exclude it. If not create a new DHCP scope for the Guest network, this can be done in your WLC if supported but not recommended. Or you may have to look in to your infra where you can have a DHCP server for this network.
11-03-2021 01:05 PM
DHCP filters will not increase security, rather they will bring lot of management problems. Also you need to keep in mind that MAC randomization is enabled on most of the devices now.
For your Guest network you need to check on your DHCP server if you have an option to exclude it. If not create a new DHCP scope for the Guest network, this can be done in your WLC if supported but not recommended. Or you may have to look in to your infra where you can have a DHCP server for this network.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide