combined dynamic/static ARP
while creating DHCP server there is option called "Enable Static ARP entries"...
When NOT ticked... each lease will have an ARP entry.
When ticked ONLY static leases will have an ARP entry.
We need it to leave the dynamic leases to have an ARP entry as it was NOT ticked... (this will enable us to prevent clients to set a static IP address on the machine & bypass firewall rules)!
or to have another option called "Enable Dynamic ARP entries"
#1 Updated by Michael F over 4 years ago
I'm not sure if it is a bug or this is the normal behavior...
As a work around I do attach another NIC to pfSense & create two DHCPs on each NIC the first is static with the options "Enable Static ARP entries" & "Deny unknown clients" ticked... the second is dynamic without those options,
both pointing to the same switch :D , with another network & subnet
the static entries get the IP from the static DHCP... & the not listed MACs get there IP from the dynamic DHCP with ARP entry.