Solved

How to block incoming traffic to my switch

Posted on 2014-03-27
3
232 Views
Last Modified: 2014-04-05
HI,

lately i have this problem where when ever my pcs connect to the LAN i get virus.

I would like to block all the traffic accept the specific server traffic i need for the pcs to access.

any one know how this can be done with cisco catalyst 2950.

i have try access-list 1 deny 192.168.1.1 but when try to ping from the pc i still can access the host ip 192.168.1.1


pls help
0
Comment
Question by:tankergoblin
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 11

Expert Comment

by:Alex Green
ID: 39958632
Rather than blocking all traffic which is essentially what you will do, have you considered upgrading your AV software so it actually works?
0
 
LVL 17

Expert Comment

by:lruiz52
ID: 39959276
Post your sanitized switch config.   I agree with Alex, check your AV software.
0
 
LVL 46

Accepted Solution

by:
Craig Beck earned 500 total points
ID: 39960288
I agree with the other experts, but if you really want to do it at the switch level you can use VLAN access-maps...

http://blog.ine.com/2009/08/10/vlan-access-control-lists-vacls-tiers-1/

You might find that your version of IOS doesn't support VLAN access-maps though, but the feature is supported on the 2950.

This will put unnecessary pressure on the switch as every single packet will need to be inspected to see where it needs to go, so it should be a last resort.
0

Featured Post

Major Incident Management Communications

Major incidents and IT service outages cost companies millions. Often the solution to minimizing damage is automated communication. Find out more in our Major Incident Management Communications infographic.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
P2P and MPLS 3 70
Trunk Port 7 71
spanning tree loop even though stp is enabled 10 93
Mac address in Nexus7K fex port 5 37
I see many questions here on Experts Exchange regarding switch port configurations and trunks. This article is meant for beginners in the subject to help to get basic knowledge about Virtual Local Area Network (VLAN (http://en.wikipedia.org/wiki/Vir…
I eventually solved a perplexing problem setting up telnet for a new switch.  I installed a new Cisco WS-03560X-24P switch connected to an existing Cisco 4506 running a WS-X4013-10GE Sup II-Plus. After configuring vlans and trunking,  I could no…
In an interesting question (https://www.experts-exchange.com/questions/29008360/) here at Experts Exchange, a member asked how to split a single image into multiple images. The primary usage for this is to place many photographs on a flatbed scanner…
How to Install VMware Tools in Red Hat Enterprise Linux 6.4 (RHEL 6.4) Step-by-Step Tutorial

740 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question