Solved

Can we restrict output to an interface using MAC filter on Cisco Catalyst 2950

Posted on 2006-11-24
8
474 Views
Last Modified: 2008-02-01
Using switchport port-security we can restrict input to an interface.
I would like to restrict output to an interface. Is that possible?
In fact I have a device connected to the switch interface and I want the device to receive packets from only 2 PCs, nothing else.
This is important to me because the device is being flooded with irrelevant packets and that is affecting its performance.
Thanks in advance for the help.
Regards,
Brian.
0
Comment
Question by:brianvanschellebeck
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
8 Comments
 
LVL 79

Accepted Solution

by:
lrmoore earned 125 total points
ID: 18007233
Unfortunately, not on a 2950.
VLAN's might be an option for you. Put these 2 PC's and this one host in their own VLAN. You might need some L3 device to allow these 2 PC's to connect to everything else at the same time. Cisco does have a concept of Private VLANS that would do what you need, but is only supported on higher-end switches and not the 2950.
0
 
LVL 50

Assisted Solution

by:Don Johnston
Don Johnston earned 125 total points
ID: 18007344
0
 

Author Comment

by:brianvanschellebeck
ID: 18007823
Can I still do it with VLAN if the two PCs are not directly connected to that switch?
In fact the twp PCs are connected to another 2950 and the two switches are connected together.
Thanks for advising.
Regards,
Brian.
0
Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
LVL 79

Expert Comment

by:lrmoore
ID: 18008001
Yes, you can use VLAN's as long as the two switches are connected by a trunk port and one is set to VTP server and one is VTP client or transparent.

0
 
LVL 16

Expert Comment

by:btassure
ID: 18077655
Do you know if you have an enhanced or a standard image on the 2950s?

If it is enhanced you can use an ACL to block access to one ip from several for example. The 2 or 3 workstations that need access would need to be on static IPs for it to work though.
0
 
LVL 79

Expert Comment

by:lrmoore
ID: 18107868
Are you still working on this? Can you close out this question before the cleanup crew gets around to it?
Thanks!
0

Featured Post

Manage your data center from practically anywhere

The KN8164V features HD resolution of 1920 x 1200, FIPS 140-2 with level 1 security standards and virtual media transmissions at twice the speed. Built for reliability, the KN series provides local console and remote over IP access, ensuring 24/7 availability to all servers.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Choice of router 8 45
Cisco 800 router unable to connect through TPG network 12 47
Router speed limit 7 105
Cisco HSRP - Do i need more than one WAN IP ? 7 52
I have seen some questions on problems with SSH/telnet access to Cisco routers that may occur despite the fact that from a PC connected to your LAN, Internet connectivity is in place and users can access Internet sites without any issues.  There are…
Creating an OSPF network that automatically (dynamically) reroutes network traffic over other connections to prevent network downtime.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

734 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question