I use combination MAC+IP, to prevent clients to change ip.
143 X ;;; OM(MAC+IP)
chain=forward action=accept src-address=192.168.76.182
src-mac-address=00:0C:42:2B:FC:55
144 X chain=forward action=log src-mac-address=00:0C:42:2B:FC:55
log-prefix="changed-ip-OM"
145 X chain=forward action=drop src-mac-address=00:0C:42:2B:FC:55
this client is using rb411+r52, but he doesnt change ip and it is showing this:
13:52:59 firewall,info info: changed-ip-OM forward: in:Local out:Local, src-
mac 00:0c:42:2b:fc:55, proto UDP, 192.168.76.181:5678-
>255.255.255.255:5678, len 93
13:52:59 firewall,info info: changed-ip-OM forward: in:Local out:Local, src-
mac 00:0c:42:2b:fc:55, proto UDP, 192
13:56:59 firewall,info info: changed-ip-OM forward: in:Local out:Local, src-
mac 00:0c:42:2b:fc:55, proto UDP, 192.168.76.181:5678-
>255.255.255.255:5678, len 93
13:56:59 firewall,info info: changed-ip-OM forward: in:Local out:Local, src-
mac 00:0c:42:2b:fc:55, proto UDP, 192.168.76.181:5678-
>255.255.255.255:5678, len 93
I use on central AP rb532, ros2.9.54, client use ros3