MAC ACL and Cat3750 - broadcasts allowed or what?

MAC ACL and Cat3750 - broadcasts allowed or what?

NewsGroups | Search | Tools

General Cisco Forum - Cisco Systems - Hardware Software and Security News and Discussions 

Bookmark this page:  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
MAC ACL and Cat3750 - broadcasts allowed or what? Piotr 09-26-2008
If you were  Registered and logged in, you could reply and use other advanced thread options
Posted by Piotr on September 26, 2008, 8:44 am


I've applied following config to the cat3750POE switch:

mac access-list extended Allowed_MACs
permit host 0007.3bc2.a111 any
permit host 001d.0900.8a14 any
permit host 0007.3bc2.4da4 any
permit host 0007.3bc2.3fea any
deny any any

interface range FastEthernet1/0/25 - 30
[CUT]
mac access-group OpenSpace_HotDesks_Allowed in

To problem is that I'm still able to get IP address from DHCP server -
ip helper address is configured. Further access
(pings/traceroute/tcp/udp) is blocked as excpected.

Is it a default behaviour or a bug? I suspect ip helper address catching
DHCP messages before the MAC ACL.

I would like to make complete traffic filtering based on MACs without
ability to get IP from DHCP. Also I want users to be able to plug into
any of those 5 ports with MAC listed on the ACL.

Any ideas?

Similar ThreadsPosted
Cat3750 temperature September 4, 2006, 9:35 am
Cat3750 ACL debugging June 11, 2007, 5:16 am
Cat3750 - flash problem September 3, 2008, 11:13 am
Command is only allowed on VLAN 2..1001. May 16, 2006, 2:46 pm
Extended VLAN(s) not allowed in current VTP mode February 7, 2007, 6:53 pm
Controlling allowed IP addresses and image differences, C3560G March 24, 2007, 5:19 pm
port channel, switchport trunk allowed vlan March 11, 2008, 9:04 pm
UDP Broadcasts filling log on PIX September 12, 2005, 1:15 pm
Regarding UDP Broadcasts and Multicasts April 6, 2006, 2:13 pm
IP Directed Broadcasts February 26, 2007, 10:42 am

other useful resources:
The Federal Communications Commission (FCC)
Telecommunications Industry Association
Electronic and Software Security Products and Services
International Telecommunication Union

Custom CGI Perl and PHP programming by 1-Script.com

Contact Us | Privacy Policy
The site map in XML format XML site map