Before you block them I'd trace the MAC through your network and try and find the source (run through the MAC address table/port mapping on your switches). Maybe also port-scan and then capture some traffic from it, check your logs etc. Your IP settings are trivial to guess once the attacker has access to a working machine, they just need to copy some details from a valid client and guess at free addresses. Usually this kind of thing is an employee bringing in their own laptops to leech internet bandwidth. More important than just blocking one MAC is stopping the practice before it spreads by making an example.
With Callout Dll and two lists of MAC addresses (one for each forest easily obtained from the DHCP MMC) keeping the clients registered to their respective forest was an easy task without the need for expensive routing/switching equipment or an IP address block change.
Otherwise yup as Dynamik said associate to a blocked IP.