From: Hossam (sam6626@yahoo.com)
Date: Wed Jun 25 2003 - 18:54:00 GMT-3
Hi Group,
I was trying to reach the optimum way to do the following requirment:
* Make Sure that NO explorers reach the MAC address 2000.2000.xxxx
where x is any number
In the begining i considerd the "DLSW icannotreach" command but,
unexpectdly (at least of me as a DLSW beginert!!) i figured out that it only
works for SAPs and not MACs!!! So i got to find another way.
My second alternative was "bridgegroup x input-address-list" or
"bridgegroup x input-address-list". I was not so sure which to use.
Intially, i thought that i have to use output-list to prevent explorers
from gettting out of the router port to the hosts. But then i figured
out that in this traffic direction the host MAC address will be in the
destination field and they will not match my access list!!!
AM i correct about this??
And If i applied input address list i think the required traffic will
be prevented (as the host replies to clients will be stoped). But then i
did't fullfil the requirement of preventing the explorers from reaching
hosst. I only prevented hosts replies!!!!
So i am almost lost now. Any corrections, or suggestions or preferably,
NEW IDEAS??
Thanks a lot
Hossam
---------------------------------
Do you Yahoo!?
SBC Yahoo! DSL - Now only $29.95 per month!
This archive was generated by hypermail 2.1.4 : Fri Jul 04 2003 - 11:11:09 GMT-3