create MAC address database and disallow nonauth'd MACS with cisco switches

Discussion in 'Cisco' started by Mike Cohen, Jul 7, 2004.

  1. Mike Cohen

    Mike Cohen Guest


    we are trying to implement a system where any non authorizes MAC
    address that plugs into our
    network either wired or wireless is denied access until the MAC is
    properly entered into the database.

    We have seen this at some universities, where students computers
    cannot navigate the LAN until they register their mac address either
    electronically, or by calling IT.

    We have cisco swtiches 2950, 3550, 4006, aironet 1200's and cisco ACS

    Can someone point me in the right directiion?


    Mike Cohen, Jul 7, 2004
  2. Mike Cohen

    Peter Payne Guest

    Port security can be implemented on Cisco 3550s and 2950s. The details
    are easily found on Cisco's website.. try this URL:
    (all one address, remove whitespace of course)

    Configuring should be straightforward:
    conf t
    int <n>
    switchport port-security
    switchport port-security maximum 1
    etc etc

    RTFM.. with the search function on the Cisco website you
    really should be doing some basic research first..
    Peter Payne, Jul 7, 2004
  3. Mike Cohen

    Peter Payne Guest

    Or even better (and this may be more what you were looking for..) MAC
    access lists on the switches (maybe on egress to the campus router).

    This would be simpler than port security as you could still plug in
    whatever you wanted to the network, just that you wouldn't be able
    to reach the default gateway (router) as the MAC ACL (access control
    list) would prevent packets from leaving the layer 2 domain into
    the layer 3 domain..
    (remove whitespace again)

    e.g. suppose you want to permit PCs with MAC addresses 0xABCDEFABCDEF and
    0x1234ABCD1234 then you might do the following:
    Switch(config-ext-macl)# permit host abcd.efab.cdef any
    Switch(config-ext-mac1)# permit host 1234.abcd.1234 any
    and then apply that list to the ingress of a trunk, or egress to a
    gateway router.

    Just food for thought.
    Peter Payne, Jul 7, 2004
  4. Mike Cohen

    Pat Donlon Guest

    Cisco have the URT tool which dynamically allocates the VLAN based on
    the mac address. I works well enough as long as you're not using IP

    Pat Donlon, Jul 7, 2004
  5. Mike Cohen

    James Guest

    Hello Mike,

    Although this is a good idea and a place to start, do not put too much
    faith in this sort of folly for real security. It's quite easy to
    purchase devices running embedded linux, that have PROGRAMMABLE Mac

    Also, older sun unix systems allow one to set the MAC address, along
    with many other systems.

    MAC addressing does cover many devices, but, a saavy hacker will laugh
    at this approach if it is intended to thawart comprimises in security
    by serious interlopers...

    James, Jul 9, 2004
  6. You don't need to be a hacker - in Win2k/XP/NT the mac address the
    network adapter uses can be modified by a network adapter property or
    - if that is not available - a simple registry entry.
    Joop van der Velden, Jul 9, 2004
  7. Mike Cohen

    chris Guest

    True, but if you need to change it to a valid address, there's a good
    chance you'll cause a conflict with the real user of that mac.
    chris, Jul 10, 2004
  8. On Cisco switches you can enable MAC security, which is what you are
    trying to do. You can also so the same with wireless. Have you tried any
    commands yet?
    John Simonetti, Jul 10, 2004
