Hi, I'm not good at english, or switches. Please be patience.
We have a few 35xx switches, no VLANS or anything fancy setup, and three notebooks...
On one switch we need on port 1, 3, 5, 7 ( wired to differend rooms ) with ONLY the three notebook MAC adress is to be allowed.
My workaround was: setting up MAC filtering on port 1 for MAC adres 1, MAC address 2 and MAC address 3, then a cheap 8 port switch connected to port 1, and from that cheap switch i've made connections to the right outlets in the rooms. It worked. Unfortunatly, the boss did not agree that it is a good workaround.
I can block MAC adressen in a ACL, but I cannot Block all, and just allow MAC 1, MAC 2 and MAC 3 .
Is there a setup for this, eighter in GUI or CLI ?
ACLs....if you write a permit rule for each of the MAC addresses, followed by a deny all, wouldn't that work??
permit any
permit any
Permit any
Deny any any
Second option....if you want to esnure that only the tree MAC addresses wil be allowed on ports 1,3 and 5, then you should be able to use Port Security.
This allows you to either learn the addresses on the ports, which you then lock, or statically configure the MAC addresses; you can choose to discard any non-compliant traffic, or shutdown the port.
Have a look at page 273 of the User Guide.
Third, , but more complex method, is to use MAC address authentication tied with authentication using RADIUS to a directory service....
The problem is, so far, that when I use 1 MAC address on port 1, I cannot assign the same MAC address also to port 2 and 3
MAC 1 must have access on port 1, 3, 5,
MAC 2 must have access on port 1, 3, 5,
MAC 3 must have access on port 1, 3, 5,
I'm afraid I have to use Radius, but I know even less about Radius than I know about the 35xx
Your second option I've use on another of our 35xx switches, and that works fine. Multiple MAC's only access through that port, or just one MAC is allowed om that specific port.
I'll try the suggested ACL as soon as possible.......
Where the Set Port is unlocked, then you have Limited Dynamic Lock chosen for a max of 3. It looks like this would allow the port to learn 3 addresses then lock. You would physically connect the three devices to each port and then it should not allow another addresses beyond the first three.
cerbera_a84f2d
176 Posts
841
0
Posted October 17th, 2012 12:00
ACLs....if you write a permit rule for each of the MAC addresses, followed by a deny all, wouldn't that work??
permit any
permit any
Permit any
Deny any any
Second option....if you want to esnure that only the tree MAC addresses wil be allowed on ports 1,3 and 5, then you should be able to use Port Security.
This allows you to either learn the addresses on the ports, which you then lock, or statically configure the MAC addresses; you can choose to discard any non-compliant traffic, or shutdown the port.
Have a look at page 273 of the User Guide.
Third, , but more complex method, is to use MAC address authentication tied with authentication using RADIUS to a directory service....