<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Blocking users using mac address in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/blocking-users-using-mac-address/m-p/1302593#M792210</link>
    <description>&lt;P&gt;I have some users on our corporate network who I need to block from the network using mac address. I can't do this via dhcp because the users are using static IPs which they keep changing once it is blocked on the PIX 515E using the shun command.&lt;/P&gt;&lt;P&gt;How can I block access to these users on the PIX. The PIX is the default gateway.&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 16:31:19 GMT</pubDate>
    <dc:creator>prince.ibe</dc:creator>
    <dc:date>2019-03-11T16:31:19Z</dc:date>
    <item>
      <title>Blocking users using mac address</title>
      <link>https://community.cisco.com/t5/network-security/blocking-users-using-mac-address/m-p/1302593#M792210</link>
      <description>&lt;P&gt;I have some users on our corporate network who I need to block from the network using mac address. I can't do this via dhcp because the users are using static IPs which they keep changing once it is blocked on the PIX 515E using the shun command.&lt;/P&gt;&lt;P&gt;How can I block access to these users on the PIX. The PIX is the default gateway.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:31:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-users-using-mac-address/m-p/1302593#M792210</guid>
      <dc:creator>prince.ibe</dc:creator>
      <dc:date>2019-03-11T16:31:19Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking users using mac address</title>
      <link>https://community.cisco.com/t5/network-security/blocking-users-using-mac-address/m-p/1302594#M792211</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You cannot block by mac-address on the PIX.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&amp;gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Oct 2009 15:34:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-users-using-mac-address/m-p/1302594#M792211</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-10-26T15:34:18Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking users using mac address</title>
      <link>https://community.cisco.com/t5/network-security/blocking-users-using-mac-address/m-p/1302595#M792212</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Andrew is right. You cannot block based on the mac-address on the PIX but, you can see if you can do this on the switch side using mac access-list&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/switches/ps646/products_configuration_example09186a0080470c39.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/switches/ps646/products_configuration_example09186a0080470c39.shtml&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Oct 2009 15:58:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-users-using-mac-address/m-p/1302595#M792212</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2009-10-26T15:58:22Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking users using mac address</title>
      <link>https://community.cisco.com/t5/network-security/blocking-users-using-mac-address/m-p/1302596#M792213</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You could also consider configuring your switch to0 use VMPS, depends on your switch platform.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you do implement VMPS - you can create a specific VLAN for these users, then either block by IP address or route them into a black hole for non lAN traffic.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Oct 2009 16:09:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-users-using-mac-address/m-p/1302596#M792213</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-10-26T16:09:30Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking users using mac address</title>
      <link>https://community.cisco.com/t5/network-security/blocking-users-using-mac-address/m-p/1302597#M792214</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have a slightly complex situation at the moment which I hope to solve in the near future.&lt;/P&gt;&lt;P&gt;I inherited a flat network. No VLANs. No DMZ. In fact, the PIX acts as the LAN gateway with only 2 ports - one inside the other outside to a router which connects to the internet via vsat modem.&lt;/P&gt;&lt;P&gt;I hope to implement some control soonest using websence but before then, I am up to my chin troubled about this particular user that frequently changes his static IP and throttles the network badly.&lt;/P&gt;&lt;P&gt;What other method can I readily deploy to cut him permanently off the network? ...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Oct 2009 19:41:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-users-using-mac-address/m-p/1302597#M792214</guid>
      <dc:creator>prince.ibe</dc:creator>
      <dc:date>2009-10-26T19:41:35Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking users using mac address</title>
      <link>https://community.cisco.com/t5/network-security/blocking-users-using-mac-address/m-p/1302598#M792215</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you can use private vlans - see the below url for config examples:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/switches/ps700/products_tech_note09186a008013565f.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/switches/ps700/products_tech_note09186a008013565f.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Put this guy's switch port in a seperate VLAN and control him this way.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Oct 2009 19:47:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-users-using-mac-address/m-p/1302598#M792215</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-10-26T19:47:28Z</dc:date>
    </item>
  </channel>
</rss>

