Hi,
after some research, I found some information about NAP (Network Access Protection) on W2008 R2 but for W2012 R2 it was deprecated...
The DHCP CallOut.DLL seems to be work only with W2008 (https://petri.com/filter-mac-address-windows-server-2008-dhcp-server-callout-dll/ ) or do I'm wrong when they say 'processing in Windows Server 2003 and later operating systems' at https://learn.microsoft.com/en-us/previous-versions/windows/desktop/dhcp/dhcp-server-api?
The main goal is: do not provide IP address to a MAC Address devices which was not previously allowed at our network.
Questions
- How to accomplish this? Just use a Switch with support for '802.1X'?
- Should we set all switches to act as Radius Client and then point them to the Domain Controller?
These steps should work??
https://support.zyxel.eu/hc/en-us/articles/4413557873810-MAC-Authentification-with-Active-Directory