cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1288
Views
5
Helpful
14
Replies

block outgoing multicast traffic on access port on nexus 3k

Ziggy74
Level 1
Level 1

Hello experts,

 

could you help me how i can block outgoing multicast form a access port in nexus 3k?

 

Thanks in advance for your help

14 Replies 14

balaji.bandi
Hall of Fame
Hall of Fame

is this something works ?

 

ip access-list extended DENYMULTICAST deny ip any 224.0.0.0 13.255.255.255
permit ip any any
!
interface ethernet x/x
ip port-acl DENYMULTICAST in or out

 

you can also use :

 

storm-control {broadcast | multicast | unicast} level percentage

 

I have tried nexus 9K

 

check if this works on your device

 

switch(config)# interface ethernet 1/2
switch(config-if)# switchport block multicast

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Hello BB,

 

thanks for your reply, i did try with acl , block and storm but didn't work, acl hadn't any match.

 

do you have any other suggestion?

 

Thanks

 

Hello,

 

what exacyly did you configure ?

 

interface ethernet 1/3
storm-control multicast level 100

 

should block all multicast traffic. If you configure that, what is the output of:


show interface ethernet 1/3 counters storm-control

 

?

Hi Georg,

 

SW1# sh int e 1/45 counters storm-control

[Action] S - Shut (Err Disable), T - Trap

--------------------------------------------------------------------------------
Port UcastSupp % McastSupp % BcastSupp % TotalSuppDiscards Action
--------------------------------------------------------------------------------
Eth1/45 100.00 100.00 100.00 0 [--]

you can try other 2 option suggested below ACL

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Hi BB,

 

i did with your first acl example but didn't work, which ac you mean now?

Optios provided in the first reply :

 

you can also use :

Opotion 2

 

storm-control {broadcast | multicast | unicast} level percentage

 

I have tried nexus 9K

Options3 :

check if this works on your device

 

switch(config)# interface ethernet 1/2
switch(config-if)# switchport block multicast

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

thanks BB,

I did , but didn't work .

 

Hello,

 

what traffic is being generated, by what multicast application ?

Hi Gerorg,

 

DVB Transport steams , video signals.

is there any configuration with filtering that i can apply on this nexus 3k?

 

Thanks in advance

provide more information of interface config ? and some log show that device still sending Multicast  to what IP address or range ?

 

is the device connected has any IP address ?

 

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Hello BB,

 

here the sh run 

 

interface Ethernet1/45
description *********L2(Multicast)*********
switchport access vlan 200
speed 1000
duplex full

Just to clarify - when yoy say not working, command not accepting or not working after command implemented.

 

what is the version of NXOS running ?

 

show version

show features

show interface eth1/45 capa

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

 

Hi BB,

not working after command implemented, here below the outputs:

 

Software
BIOS: version 4.0.0
NXOS: version 7.0(3)I4(7)
BIOS compile time: 12/05/2016
NXOS image file is: bootflash:///nxos.7.0.3.I4.7.bin
NXOS compile time: 6/28/2017 14:00:00 [06/28/2017 21:53:29]


Hardware
cisco Nexus3000 C3064PQ Chassis
Intel(R) Celeron(R) CPU P4505 @ 1.87GHz with 3903284 kB of memory.
Processor Board ID FOC17372DSZ

Device name: NTFRA-SW1
bootflash: 1638000 kB
usb1: 0 kB (expansion flash)

Kernel uptime is 1023 day(s), 0 hour(s), 50 minute(s), 53 second(s)

Last reset at 871694 usecs after Thu Feb 15 11:40:06 2018

Reason: Reset Requested by CLI command reload
System version: 7.0(3)I4(7)
Service:

plugin
Core Plugin, Ethernet Plugin

Active Package(s):


--------------------------------------------------------------

SW1# sh feature
Feature Name Instance State
-------------------- -------- --------
bash-shell 1 disabled
bfd 1 disabled
bgp 1 disabled
dhcp 1 disabled
eigrp 1 disabled
eigrp 2 disabled
eigrp 3 disabled
eigrp 4 disabled
hsrp_engine 1 disabled
imp 1 disabled
interface-vlan 1 enabled
isis 1 disabled
isis 2 disabled
isis 3 disabled
isis 4 disabled
isis 5 disabled
isis 6 disabled
isis 7 disabled
isis 8 disabled
isis 9 disabled
isis 10 disabled
isis 11 disabled
isis 12 disabled
isis 13 disabled
isis 14 disabled
isis 15 disabled
isis 16 disabled
lacp 1 disabled
ldp 1 disabled
lldp 1 enabled
mpls_static 1 disabled
msdp 1 disabled
nve 1 disabled
nxapi 1 disabled
of_agent 1 disabled
onep 1 disabled
ospf 1 disabled
ospf 2 disabled
ospf 3 disabled
ospf 4 disabled
ospfv3 1 disabled
ospfv3 2 disabled
ospfv3 3 disabled
ospfv3 4 disabled
pbr 1 disabled
pim 1 enabled (not-running)
private-vlan 1 disabled
privilege 1 disabled
ptp 1 disabled
rip 1 disabled
rip 2 disabled
rip 3 disabled
rip 4 disabled
scheduler 1 disabled
scpServer 1 disabled
segment-routing 1 disabled
sflow 1 disabled
sftpServer 1 disabled
sshServer 1 enabled
tacacs 1 disabled
telnetServer 1 enabled
tunnel 1 disabled
udld 1 disabled
vmtracker 1 disabled
vni 1 disabled
vnseg_vlan 1 disabled
vpc 1 enabled
vrrp 1 disabled
vrrpv3 1 disabled
vtp 1 disabled

-------------------------------------------------------

SW1# sh int e 1/45 capabilities
Ethernet1/45
Model: N3K-C3064PQ-10GX
Type (SFP capable): 1000base-X
Speed: 100,1000,10000
Duplex: full
Trunk encap. type: 802.1Q
Channel: yes
Broadcast suppression: percentage(0-100)
Flowcontrol: rx-(off/on),tx-(off/on)
Rate mode: dedicated
Port mode: Routed,Switched
QOS scheduling: rx-(8q2t),tx-(7q)
CoS rewrite: yes
ToS rewrite: yes
SPAN: yes
UDLD: yes
MDIX: no
TDR capable: no
Link Debounce: yes
Link Debounce Time: yes
FEX Fabric: yes
dot1Q-tunnel mode: yes
Pvlan Trunk capable: no
Port Group Members: none
EEE (efficient-eth): no
PFC capable: no
Buffer Boost capable: yes
Breakout capable: no
MACSEC capable: no

Review Cisco Networking for a $25 gift card