Layer 2 traffic filtering can be very useful when you want to drop packets closer to
the source because you can do this on L2 next-hop which is the switch where the
devices are connected. Based on mac-address, Layer 2 filtering can be apply using
one of the two most common method: Port Security and MAC Access Groups.
Port Security is the more secure method of the two. To use it, map a switch port to the
specific MAC address of the connected device. It gives you more possibility than just
drop the packets from a specific source, depending on what you want to achieve on
the interface where it is applied.
MAC Access Groups are generally used for small networks of 20 devices or less. Add
a permit statement for all of your devices interface MAC addresses and apply the access
list to switch interface. This will limit inbound traffic to that interface to only those
MAC addresses on your list. Is not recommended when you have many MAC addresses,
because MAC access-list are the same like IP address access-list, so they consume a
lot of resources of the machine where it is applied.
For this tutorial we will use a Cisco 3750 in which it is connected a router ( R4 ). To test
Layer 2 traffic filtering, we have a point-to-point Layer 3 connection in between
( 10.0.0.0 /30 ), with physical interface used on the R4 and a Vlan 4 interface on the
switch. The port on the switch were R4 is connected is an access port in vlan 4.
Please see the tutorial below:
- http://www.secrel.com.br Daniel Gurgel
Which WAN Optimization vendor will consolidate and expand its market position on 2011
447 votes - Thank you all!I add the results in a blog posts so we can see over years on which [more]
CCIE home rack - Ubuntu persistent net rules
In one of my last posts, I was writing about my CCIE home rack which has one server that runs Ubuntu + [more]
Black Friday 2011 - 50% Off on INE bundles
If anybody is interested in buying INE products, do it now. I've got the following marketing e-mail. The [more]
Free streaming course CCNA 640-802 from INE
I'm sure that a lot of people out there got this info already, but for those who are not part of INE [more]
Home lab for CCIE exam training
Before I started with my preparation I was in front of a dilemma. I knew that I will need a rack to [more]
Professionals Blogs
- packetlife.net
Close preview
Loading... - gns3-labs.com
Close preview
Loading... - Cisco Network Engineer Blog
Close preview
Loading... - mellowd.co.uk
Close preview
Loading... - CCIECisco
Close preview
Loading... - brainbump.net
Close preview
Loading... - danielhertzberg.wordpress.com
Close preview
Loading... - globalconfig.net
Close preview
Loading... - packet-forwarding.net
Close preview
Loading... - blog.ioshints.info
Close preview
Loading... - routing-bits.com
Close preview
Loading... - etherealmind.com
Close preview
Loading... - noshut.blogspot.com
Close preview
Loading... - amyengineer.wordpress.com
Close preview
Loading... - cisco-tips.com
Close preview
Loading... - bradhedlund.com
Close preview
Loading... - blindhog.net
Close preview
Loading...
- packetlife.net





