DHCP MAC Filters¶
MAC filters let you permit or deny DHCP leases based on hardware address. A filter is a named list of MAC addresses; networks and ranges reference the filter by name.
MAC Filter lifecycle¶
- Create the filter:
configure network macfilter add <name> - Add MAC addresses to it:
configure network filter <name> add macaddress <mac> - Assign the filter to a range or network (via the WAPI GUI or a direct WAPI call - ibcli does not yet have a
configure network range set filtercommand).
show network filter¶
List all MAC filters, or show MAC addresses in a specific filter.
Syntax:
WAPI: GET filtermac (list) or GET macfilteraddress?filter=<ref> (addresses)
configure network macfilter add¶
Create a new MAC filter.
Syntax:
WAPI: POST filtermac
configure network macfilter delete¶
Delete a MAC filter (and all its MAC address entries).
Syntax:
WAPI: GET filtermac?name=<name> then DELETE <ref>
Note
Deleting a filter while it is referenced by a range or network may leave those objects with a dangling filter reference. Remove the filter reference from the range first.
configure network filter \<name> add macaddress¶
Add a MAC address to an existing filter.
Syntax:
WAPI: Resolves the filter _ref, then POST macfilteraddress
MAC addresses are normalised to colon-separated lowercase by ibcli.
configure network filter \<name> delete macaddress¶
Remove a MAC address from a filter.
Syntax:
WAPI: Resolves the filter _ref, looks up macfilteraddress?mac=<mac>&filter=<ref>, then DELETE <addr_ref>
Related commands¶
- DHCP Ranges - ranges that reference MAC filters for access control.
- Fixed Addresses - per-IP reservations (alternative to filter-based assignment).