cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
344
Views
0
Helpful
2
Replies

Port Security on 3550 based on given MAC-Address and IP-Address

mknorz
Level 1
Level 1

How can I configure PortSecurity based on MAc-Address and IP-Address..... I only know about "switchport port-security mac-address" but there must be a way to manage this in conjunction with an IP.... Static ARp entry ????

1 Accepted Solution

Accepted Solutions

t.baranski
Level 4
Level 4

A static ARP entry will only come into play when routing is taking place. So, for traffic that is switched instead of routed (traffic destined to the source's subnet), the source IP doesn't come into play, and is hence irrelevant to the switch. But, even with layer-3 traffic, a static ARP entry doesn't do the trick because it doesn't stop the host with the secure MAC address from using a different IP address -- it only stops another host (with a different MAC address) from using the secure host's IP.

Therefore, the only way that I can see to allow traffic only from "secure" IP addresses is to configure an IP access list for each switch port, and use it in conjuction with port security.

View solution in original post

2 Replies 2

t.baranski
Level 4
Level 4

A static ARP entry will only come into play when routing is taking place. So, for traffic that is switched instead of routed (traffic destined to the source's subnet), the source IP doesn't come into play, and is hence irrelevant to the switch. But, even with layer-3 traffic, a static ARP entry doesn't do the trick because it doesn't stop the host with the secure MAC address from using a different IP address -- it only stops another host (with a different MAC address) from using the secure host's IP.

Therefore, the only way that I can see to allow traffic only from "secure" IP addresses is to configure an IP access list for each switch port, and use it in conjuction with port security.

Thanx for the reply, I think that will solve the problem !!!!!

regards

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: