> But since it would appear that security through MAC address limitation
> is rather moot (MACs being as easily sniffed as they are spoofed), I see
> no really important reason for going out of the way to prevent that
> single dynamic IP from being available on the LAN, as one can simply
> choose not to utilize it (as in my case, where all my hosts have a
> corrosponding entry in the static mappings list), with little to no
> resulting overhead of any kind. (But of course, I might be missing some
> good reason for avoiding this situation?)
Hi Adam,
Very good points you bring up... but my main reason for this feature is
that I have two m0n0wall subnets on the same (unmanaged) switch and
would like to be able to define each clients subnet by mac address
(server side with the benefits of dhcp) :) |