Solved

Cisco 2821 Internet Filtering using Mac Address

Posted on 2009-05-16
3
751 Views
Last Modified: 2013-11-16
Experts, i have new cisco 2821, i'm using it as default router using ADSL connection, now the boss want me to stop few computer accessing internet via cisco rules and some computer stop only internet but not oputlook email. any recommendation? i probably wants mac add filtering if possible...
0
Comment
Question by:tropicmar
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 7

Expert Comment

by:diepes
ID: 24405642
The problem is the router only supports L3/IP access lists.
If the pc's have fixed IP's, either static config, or set same ip in DHCP (based on mac) you can add a acl to block the IP's

I assume the router is only used for Internet access.

If the router plugs into a Cisco switch you can do mac filtering on the Cisco switch port connecting to the router.


0
 
LVL 13

Accepted Solution

by:
Quori earned 500 total points
ID: 24407744
It is possible to do this.

Simply put the port into layer 2 mode (via switchport).
Remove the layer 3 details.
Configure your layer 2 details on the physical port.
Enable intelligent bridging (bridge irb)
Create a BVI
Configure layer 3 details on the new BVI logical interface
Apply a MAC ACL to the BVI.

As an example:

bridge irb
!
interface FastEthernet0/0
no ip address
no ip route-cache
no ip mroute-cache
bridge-group 1
no shut
!
interface BVI1
ip address 1.1.1.1 255.255.255.0
!
bridge 1 protocol ieee
bridge 1 route ip
bridge 1 address aabb.ccdd.eeff discard
!
end
0
 
LVL 13

Expert Comment

by:Quori
ID: 24407767
Note the above would drop pretty much all traffic from the MAC specified.

With what you're attempting to do, you'd be best off using VLANs, and managing it that way, then use layer 3 ACLs for filtering on the specific subnets. This would be far less administrative overhead in the long run.
0

Featured Post

Free Tool: Path Explorer

An intuitive utility to help find the CSS path to UI elements on a webpage. These paths are used frequently in a variety of front-end development and QA automation tasks.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Wikipedia defines 'Script Kiddies' in this informal way: "In hacker culture, a script kiddie, occasionally script bunny, skiddie, script kitty, script-running juvenile (SRJ), or similar, is a derogatory term used to describe those who use scripts or…
This article offers some helpful and general tips for safe browsing and online shopping. It offers simple and manageable procedures that help to ensure the safety of one's personal information and the security of any devices.
In a recent question (https://www.experts-exchange.com/questions/29004105/Run-AutoHotkey-script-directly-from-Notepad.html) here at Experts Exchange, a member asked how to run an AutoHotkey script (.AHK) directly from Notepad++ (aka NPP). This video…
I've attached the XLSM Excel spreadsheet I used in the video and also text files containing the macros used below. https://filedb.experts-exchange.com/incoming/2017/03_w12/1151775/Permutations.txt https://filedb.experts-exchange.com/incoming/201…

733 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question