IP/MAC Binding on Flex H series

QuiteSmart
QuiteSmart Posts: 66  Ally Member
Zyxel Certified Network Administrator - Nebula Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - WLAN

Hello community,

is it possible to configure IP/MAC binding as it is in the "interface" settings of the ATP GUI?

I cannot find it, nor on-premise nor in the nebula configuration

I found a more or less recent FAQ about MAC binding here but it just refers to the ATP GUI.

Thanks😜

Accepted Solution

  • PeterUK
    PeterUK Posts: 3,969  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary
    edited August 23 Answer ✓

    So tested it out seems to work "Source IP Spoofing Prevention" where by any static IPs are blocked unless allowed by Trusted IP.

    and any Reserved IP/MAC that you make static are allowed even if not in Trusted IP but with Include DHCP Leasing Entries on

All Replies

  • Zyxel_Melen
    Zyxel_Melen Posts: 3,666  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @QuiteSmart

    This feature is renamed as "IP Spoofing Prevention."

    image.png

    FAQ: USG FLEX H Series - Source IP Spoofing Prevention — Zyxel Community

    Zyxel Melen


  • QuiteSmart
    QuiteSmart Posts: 66  Ally Member
    Zyxel Certified Network Administrator - Nebula Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - WLAN

    Then you @Zyxel_Melen ,

    does it work even when some mac addresses have the IP locked with DHCP reservation?

  • PeterUK
    PeterUK Posts: 3,969  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary
    edited August 22

    guess thats what the "Include DHCP Leasing Entries" toggle is?

    unless your looking for this?

    Screenshot 2025-08-22 181335.png
  • QuiteSmart
    QuiteSmart Posts: 66  Ally Member
    Zyxel Certified Network Administrator - Nebula Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - WLAN

    Hello @PeterUK I hope you had/are having nice vacations,

    I must admit that since @Zyxel_Melen reply I still have to test it

    What I would like to get is the following:

    1. DHCP is on that interface
    2. I have some devices with DHCP reservation in place (like in @PeterUK screenshot)
    3. In case a host connects with DHCP he is alllowed
    4. In case a host connects with a static IP it is banned and log alert reported
    5. Hosts with DHCP reservation are allowed and DHCP reservation takes place
    6. Eventually (since i saw something that seems alike) i can whitelist some ip addresses (in case a host presents itself with that static IP it is allowed)

    It seems to me that everything can be done I just wanted to double check on the DHCP reserved hosts since AFAIK on ATP series they were not allowed in such a scenario

  • PeterUK
    PeterUK Posts: 3,969  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary

    SO your looking for the "Enable IP/MAC Binding and DHCP Enforcement" ?

  • PeterUK
    PeterUK Posts: 3,969  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary
    edited August 23 Answer ✓

    So tested it out seems to work "Source IP Spoofing Prevention" where by any static IPs are blocked unless allowed by Trusted IP.

    and any Reserved IP/MAC that you make static are allowed even if not in Trusted IP but with Include DHCP Leasing Entries on

  • QuiteSmart
    QuiteSmart Posts: 66  Ally Member
    Zyxel Certified Network Administrator - Nebula Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - WLAN

    your "guru member" status is well deserved, thank you mate!