Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Can we restrict output to an interface using MAC filter on Cisco Catalyst 2950

Posted on 2006-11-24
8
Medium Priority
?
493 Views
Last Modified: 2008-02-01
Using switchport port-security we can restrict input to an interface.
I would like to restrict output to an interface. Is that possible?
In fact I have a device connected to the switch interface and I want the device to receive packets from only 2 PCs, nothing else.
This is important to me because the device is being flooded with irrelevant packets and that is affecting its performance.
Thanks in advance for the help.
Regards,
Brian.
0
Comment
Question by:brianvanschellebeck
6 Comments
 
LVL 79

Accepted Solution

by:
lrmoore earned 500 total points
ID: 18007233
Unfortunately, not on a 2950.
VLAN's might be an option for you. Put these 2 PC's and this one host in their own VLAN. You might need some L3 device to allow these 2 PC's to connect to everything else at the same time. Cisco does have a concept of Private VLANS that would do what you need, but is only supported on higher-end switches and not the 2950.
0
 
LVL 50

Assisted Solution

by:Don Johnston
Don Johnston earned 500 total points
ID: 18007344
0
 

Author Comment

by:brianvanschellebeck
ID: 18007823
Can I still do it with VLAN if the two PCs are not directly connected to that switch?
In fact the twp PCs are connected to another 2950 and the two switches are connected together.
Thanks for advising.
Regards,
Brian.
0
Concerto Cloud for Software Providers & ISVs

Can Concerto Cloud Services help you focus on evolving your application offerings, while delivering the best cloud experience to your customers? From DevOps to revenue models and customer support, the answer is yes!

Learn how Concerto can help you.

 
LVL 79

Expert Comment

by:lrmoore
ID: 18008001
Yes, you can use VLAN's as long as the two switches are connected by a trunk port and one is set to VTP server and one is VTP client or transparent.

0
 
LVL 16

Expert Comment

by:btassure
ID: 18077655
Do you know if you have an enhanced or a standard image on the 2950s?

If it is enhanced you can use an ACL to block access to one ip from several for example. The 2 or 3 workstations that need access would need to be on static IPs for it to work though.
0
 
LVL 79

Expert Comment

by:lrmoore
ID: 18107868
Are you still working on this? Can you close out this question before the cleanup crew gets around to it?
Thanks!
0

Featured Post

How to Use the Help Bell

Need to boost the visibility of your question for solutions? Use the Experts Exchange Help Bell to confirm priority levels and contact subject-matter experts for question attention.  Check out this how-to article for more information.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I have seen some questions on problems with SSH/telnet access to Cisco routers that may occur despite the fact that from a PC connected to your LAN, Internet connectivity is in place and users can access Internet sites without any issues.  There are…
Shadow IT is coming out of the shadows as more businesses are choosing cloud-based applications. It is now a multi-cloud world for most organizations. Simultaneously, most businesses have yet to consolidate with one cloud provider or define an offic…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

876 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question