Solved

Can we restrict output to an interface using MAC filter on Cisco Catalyst 2950

Posted on 2006-11-24
8
449 Views
Last Modified: 2008-02-01
Using switchport port-security we can restrict input to an interface.
I would like to restrict output to an interface. Is that possible?
In fact I have a device connected to the switch interface and I want the device to receive packets from only 2 PCs, nothing else.
This is important to me because the device is being flooded with irrelevant packets and that is affecting its performance.
Thanks in advance for the help.
Regards,
Brian.
0
Comment
Question by:brianvanschellebeck
8 Comments
 
LVL 79

Accepted Solution

by:
lrmoore earned 125 total points
Comment Utility
Unfortunately, not on a 2950.
VLAN's might be an option for you. Put these 2 PC's and this one host in their own VLAN. You might need some L3 device to allow these 2 PC's to connect to everything else at the same time. Cisco does have a concept of Private VLANS that would do what you need, but is only supported on higher-end switches and not the 2950.
0
 
LVL 50

Assisted Solution

by:Don Johnston
Don Johnston earned 125 total points
Comment Utility
0
 

Author Comment

by:brianvanschellebeck
Comment Utility
Can I still do it with VLAN if the two PCs are not directly connected to that switch?
In fact the twp PCs are connected to another 2950 and the two switches are connected together.
Thanks for advising.
Regards,
Brian.
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 
LVL 79

Expert Comment

by:lrmoore
Comment Utility
Yes, you can use VLAN's as long as the two switches are connected by a trunk port and one is set to VTP server and one is VTP client or transparent.

0
 
LVL 16

Expert Comment

by:btassure
Comment Utility
Do you know if you have an enhanced or a standard image on the 2950s?

If it is enhanced you can use an ACL to block access to one ip from several for example. The 2 or 3 workstations that need access would need to be on static IPs for it to work though.
0
 
LVL 79

Expert Comment

by:lrmoore
Comment Utility
Are you still working on this? Can you close out this question before the cleanup crew gets around to it?
Thanks!
0

Featured Post

Better Security Awareness With Threat Intelligence

See how one of the leading financial services organizations uses Recorded Future as part of a holistic threat intelligence program to promote security awareness and proactively and efficiently identify threats.

Join & Write a Comment

I have seen some questions on problems with SSH/telnet access to Cisco routers that may occur despite the fact that from a PC connected to your LAN, Internet connectivity is in place and users can access Internet sites without any issues.  There are…
Hello , This is a short article on how would you go about enabling traceoptions on a Juniper router . Traceoptions are similar to Cisco debug commands but these traceoptions are implemented in Juniper networks router . The following demonstr…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

763 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now