Best way to prevent unauthorized ex-clients accessing i-net.

Hi all.

Have some question about protection against unauthorized ex-clients. Here is situation: Ex-client who has copied all neighbor list internal IP and MAC addresses (/ip neighbor>print). Hi can change his Wlan MAC to authorized client MAC (those who are on AP Access list) and changing IP, hi is able to use internet while real MAC address owner is not using internet. Course it’s not best way to steal internet. But anyway, i need solution for this situation.

On AP there is dynamic ARP address for each client and Access list.
Should i create securery profile with Radius MAC authentication, Mac accountig to prevent this?

Regards.

Can you use a simple hotspot? If he don’t know a user he can’t enter..

MAC+hotspot with user/password.

Ok, gonna try it out next month. Thanks