From: ccie1@hotmail.com
Date: Tue Mar 18 2003 - 12:45:07 GMT-3
Hi Tim:
Thanks for the response. One part of the question involves and IP
address as well. I see you put the ip address under the VLAN 100 interface.
The question doesnt specify a particular vlan, and the question also
mentioned a "host" with ip address 12.3.1.1.I think configuring a vlan would
be more config then needed and would not be allowed in the lab.
----- Original Message -----
From: "Tim Fletcher" <tim@fletchmail.net>
To: <ccie1@hotmail.com>; <ccielab@groupstudy.com>
Sent: Monday, March 17, 2003 12:51 PM
Subject: Re: port filtering
> Here's a simple solution. I don't know if there are any other requirements
> that might make this solution invalid.
>
> interface FastEthernet 0/16
> switchport port-security maximum 1
> switchport port-security mac-address 0800.E4D3.A2D1
> switchport access vlan 100
> !
> interface Vlan100
> ip address 12.3.1.2 255.255.255.252
>
> Any thoughts?
>
> -Tim Fletcher
>
> At 08:10 AM 3/17/2003 -0800, ccie1@hotmail.com wrote:
> >I know this has been discussed before, but i have tried some of the
solutions
> >people have posted and they dont seem to work:
> >
> >I want to only allow mac-address 0800.E4D3.A2D1 with ip address 12.3.1.1
on
> >port fast-etjhernet 0/16 on my 3550. The requirement is to not use layer
3 or
> >layer 2 access-lists. I tried using port-security with the mac-address
but
> >that doesnt seem to work. Does anyone have any ideas on how to do this?
> >
> >thanks in advance
This archive was generated by hypermail 2.1.4 : Sat Apr 05 2003 - 08:51:41 GMT-3