cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
512
Views
0
Helpful
2
Replies

Same mac address in many ports

jeremy.hidoux
Level 1
Level 1

Hello,

I would like to set security port (type shutdown) with the same mac address. But this mac address should be present on many ports of this same switch.

Have you a solution to realize this configuration ?

Actually, if i set up the same mac address, the ios say to me "duplicate entry" and refuse my command.

Thank you.

2 Replies 2

nspasov
Cisco Employee
Cisco Employee

Can you elaborate a bit more on what you are trying to accomplish here. Also, perhaps share some of the configuration(s) that you are having issues with.

Thank you for rating helpful posts!

Thank you for rating helpful posts!

Marvin Rhoads
Hall of Fame
Hall of Fame

If I understand correctly you want to prevent a given MAC address no matter what port it shows up on. With ISE we would call this "blacklisting" and could enforce ti dynamically across the network.

Without ISE, you could use the order method of an access-list specifying a MAC address. You then apply that access list your interfaces.

access-list 700 deny <mac address> 0000.0000.0000
access-list 700 permit 0000.0000.0000 ffff.ffff.ffff 
You can also use named extended MAC ACLs:

http://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst3560/software/release/12-2_55_se/configuration/guide/3560_scg/swacl.html#wp1289037
Review Cisco Networking for a $25 gift card