  1. kware

    kware Guest


    We are trying to prevent unauthorised users from connecting PC's to the
    network and obtaining access to domain resources and the Internet.

    We are using Cisco 2950 switches on a Windows 2000 domain.

    My question is, can we allow traffic from only known (and pre-approved)
    MAC addresses?

    Any ideas?

    Thanks in advance
    kware, Jul 8, 2005
  2. On 08.07.2005 17:23 wrote
    you can do, but you also should know that MAC addresses may be spoofed
    easily (e.g.

    You might want to look into 802.1X instead

    Arnold Nipper, Jul 8, 2005
  3. kware

    big si Guest

    Another option is port security, but a big admin overhead.
    MAC addresses are defined and allowed access only on specific interfaces.

    Not good in a 'hot desk' environment.


    interface FastEthernet0/2
    description desktop
    switchport mode access
    switchport port-security
    switchport port-security aging time 2
    switchport port-security violation restrict
    switchport port-security aging type inactivity
    switchport port-security mac-address sticky
    switchport port-security mac-address sticky 0000.3911.c3f4
    mls qos cos override
    macro description cisco-desktop
    spanning-tree portfast
    spanning-tree bpduguard enable

    Big Si.
    big si, Jul 10, 2005
