cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1335
Views
0
Helpful
6
Replies

Block an PC from Switch

abithbasha
Level 1
Level 1

Dear All,

I have virus infected PC in the network, I want to block this PC from network, I can shut down the port but if the PC connects to another switch port then it will spread virus, so I have MAC address b870.f400.7979 and I wanted to block this MAC from our network, which ever port this MAC connects then that port should drop this or not allow this on our network

6 Replies 6

shijomon scaria
Level 1
Level 1

Hi,

Port security can be an option for you, but the effort varies according to the size of your network.

Regards,

Shijo.

It is small office, so can you give me a option or commands how to block it on the network

the PC MAC  address is this b870.f400.7979

Hi,

Instead of blocking that particular mac, in port security we are adding trusted macs to ports using different methods, and sets the rule if the conditions violates.

Example.

SWITCH(config)# int Gi0/1
SWITCH(config-if)#switchport port-security
SWITCH(config-if)#switchport port-security mac-address 0000.aaaa.bbbb
SWITCH(config-if)#switchport port-security violation shutdown

Refer below document.

http://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst4500/12-2/25ew/configuration/guide/conf/port_sec.pdf

 

Regards,

Shijo.

 

 

 

Hi,

 

And the other option is MAC ACLS

 

Regards,

Shijo.

Hi,

 

Can I have link or commands for MAC ACLS?

Hi,

 

http://www.cisco.com/c/en/us/td/docs/switches/datacenter/sw/4_1/nx-os/security/configuration/guide/sec_nx-os-cfg/sec_macacls.pdf

 

Regards,

Shijo

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: