<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic I'm using the CIsco Router in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/need-to-figure-out-how-to-block-a-mac-address/m-p/2507651#M921794</link>
    <description>&lt;P&gt;I'm using the CIsco Router itself as the DHCP server.&lt;/P&gt;</description>
    <pubDate>Sun, 05 Oct 2014 01:52:21 GMT</pubDate>
    <dc:creator>David Lee</dc:creator>
    <dc:date>2014-10-05T01:52:21Z</dc:date>
    <item>
      <title>Need to figure out how to block a MAC address</title>
      <link>https://community.cisco.com/t5/network-security/need-to-figure-out-how-to-block-a-mac-address/m-p/2507649#M921790</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to block a certain MAC address from either getting an IP via DHCP, or if not possible from accessing the network. &amp;nbsp;I have remote locations with Cisco routers, but not all of them have Cisco switches. &amp;nbsp;What I am finding is that some people are plugging in their personal laptops and devices to the network. &amp;nbsp;Since I have caught them and obtained the MAC address from the DHCP bindings, I am wanting to put in some kind of rule to block them. &amp;nbsp;I have asked them, but they blatantly disregard me. &amp;nbsp;If I have something in the router, they can't get around that. &amp;nbsp;I tried to create an access-list 700 to block the mac, but that didn't seem to work. &amp;nbsp;I have tried this on a Cisco 1841, 1921, and 2901 and it did not work. &amp;nbsp;Any pointers on how to block a particular MAC address, or a few from doing anything with a Cisco router running the location but without a Cisco Switch is greatly appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;David&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 13:18:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-to-figure-out-how-to-block-a-mac-address/m-p/2507649#M921790</guid>
      <dc:creator>David Lee</dc:creator>
      <dc:date>2020-02-21T13:18:02Z</dc:date>
    </item>
    <item>
      <title>Short of having a full-blown</title>
      <link>https://community.cisco.com/t5/network-security/need-to-figure-out-how-to-block-a-mac-address/m-p/2507650#M921792</link>
      <description>&lt;P&gt;Short&amp;nbsp;of having a full-blown network access control system like Cisco ISE, it's much easier to do this on your DHCP server but whether or not you can do that depends on the type of server you are using.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Oct 2014 22:33:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-to-figure-out-how-to-block-a-mac-address/m-p/2507650#M921792</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2014-10-03T22:33:23Z</dc:date>
    </item>
    <item>
      <title>I'm using the CIsco Router</title>
      <link>https://community.cisco.com/t5/network-security/need-to-figure-out-how-to-block-a-mac-address/m-p/2507651#M921794</link>
      <description>&lt;P&gt;I'm using the CIsco Router itself as the DHCP server.&lt;/P&gt;</description>
      <pubDate>Sun, 05 Oct 2014 01:52:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-to-figure-out-how-to-block-a-mac-address/m-p/2507651#M921794</guid>
      <dc:creator>David Lee</dc:creator>
      <dc:date>2014-10-05T01:52:21Z</dc:date>
    </item>
    <item>
      <title>You can't exclude a MAC</title>
      <link>https://community.cisco.com/t5/network-security/need-to-figure-out-how-to-block-a-mac-address/m-p/2507652#M921795</link>
      <description>&lt;P&gt;You can't exclude a MAC address directly per se on the IOS DHCP server.&lt;/P&gt;&lt;P&gt;You might be able to achieve your goal by giving it a manual binding on an invalid subnet - essentially "black holing" the host.&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/ios/12_2/ip/configuration/guide/fipr_c/1cfdhcp.html#wp1017385"&gt;Link for configuring manual binding&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Sun, 05 Oct 2014 14:56:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-to-figure-out-how-to-block-a-mac-address/m-p/2507652#M921795</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2014-10-05T14:56:20Z</dc:date>
    </item>
    <item>
      <title>That worked.  I didn't even</title>
      <link>https://community.cisco.com/t5/network-security/need-to-figure-out-how-to-block-a-mac-address/m-p/2507653#M921796</link>
      <description>&lt;P&gt;That worked.&amp;nbsp; I didn't even think of trying to Black Hole them.&amp;nbsp;&amp;nbsp; Thank You.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Oct 2014 16:17:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-to-figure-out-how-to-block-a-mac-address/m-p/2507653#M921796</guid>
      <dc:creator>David Lee</dc:creator>
      <dc:date>2014-10-13T16:17:45Z</dc:date>
    </item>
    <item>
      <title>OK, I tohught it worked but</title>
      <link>https://community.cisco.com/t5/network-security/need-to-figure-out-how-to-block-a-mac-address/m-p/2507654#M921797</link>
      <description>&lt;P&gt;OK, I thought it worked but it appears to not have.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;172.16.101.1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 01c8.3a35.21be.28&amp;nbsp;&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Infinite&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Manual&lt;BR /&gt;192.168.15.30&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0100.1e0b.8239.cf&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Infinite&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Manual&lt;BR /&gt;192.168.15.31&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0010.1f29.db84.0d&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Infinite&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Manual&lt;BR /&gt;&lt;STRONG&gt;192.168.15.150&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 01c8.3a35.21be.28&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Oct 14 2014 01:55 AM&amp;nbsp;&amp;nbsp;&amp;nbsp; Automatic&lt;/STRONG&gt;&lt;BR /&gt;192.168.15.151&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0100.1f29.db84.0d&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Oct 14 2014 12:35 AM&amp;nbsp;&amp;nbsp;&amp;nbsp; Automatic&lt;BR /&gt;192.168.15.152&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0100.e0bb.2631.2c&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Oct 14 2014 10:21 AM&amp;nbsp;&amp;nbsp;&amp;nbsp; Automatic&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I created the black hole of the 172 address, but it still got a working IP address of 192.168.15.150.&amp;nbsp; How could it still get a valid IP?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Oct 2014 16:22:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-to-figure-out-how-to-block-a-mac-address/m-p/2507654#M921797</guid>
      <dc:creator>David Lee</dc:creator>
      <dc:date>2014-10-13T16:22:41Z</dc:date>
    </item>
    <item>
      <title>Let him have a 192.168.15.x</title>
      <link>https://community.cisco.com/t5/network-security/need-to-figure-out-how-to-block-a-mac-address/m-p/2507655#M921798</link>
      <description>&lt;P&gt;Let him have a 192.168.15.x address but blackhole that /32. i.e.:&lt;/P&gt;&lt;P&gt;&lt;CODE&gt;ip route 192.168.15.150 255.255.255.255 null0&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Oct 2014 03:04:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-to-figure-out-how-to-block-a-mac-address/m-p/2507655#M921798</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2014-10-14T03:04:16Z</dc:date>
    </item>
    <item>
      <title>That did it.  Thank you</title>
      <link>https://community.cisco.com/t5/network-security/need-to-figure-out-how-to-block-a-mac-address/m-p/2507656#M921799</link>
      <description>&lt;P&gt;That did it.&amp;nbsp; Thank you Marvin&lt;/P&gt;</description>
      <pubDate>Wed, 15 Oct 2014 19:42:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-to-figure-out-how-to-block-a-mac-address/m-p/2507656#M921799</guid>
      <dc:creator>David Lee</dc:creator>
      <dc:date>2014-10-15T19:42:35Z</dc:date>
    </item>
    <item>
      <title>c2900-universalk9-mz.SPA.150</title>
      <link>https://community.cisco.com/t5/network-security/need-to-figure-out-how-to-block-a-mac-address/m-p/2507657#M921800</link>
      <description>&lt;P&gt;c2900-universalk9-mz.SPA.150-1.M1 -&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;class-map match-any internal-block&lt;BR /&gt;&amp;nbsp;match source-address mac 1234.1234.1234&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;policy-map block-policy&lt;BR /&gt;&amp;nbsp;class internal-block&lt;BR /&gt;&amp;nbsp;&amp;nbsp; drop&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/0&lt;BR /&gt;&amp;nbsp;description LAN interface&lt;/P&gt;&lt;P&gt;service-policy input block-policy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Apr 2015 15:16:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-to-figure-out-how-to-block-a-mac-address/m-p/2507657#M921800</guid>
      <dc:creator>wayfaring</dc:creator>
      <dc:date>2015-04-20T15:16:17Z</dc:date>
    </item>
  </channel>
</rss>

