12-04-2020 01:40 AM
Hello experts,
could you help me how i can block outgoing multicast form a access port in nexus 3k?
Thanks in advance for your help
12-04-2020 02:14 AM
is this something works ?
ip access-list extended DENYMULTICAST deny ip any 224.0.0.0 13.255.255.255
permit ip any any
!
interface ethernet x/x
ip port-acl DENYMULTICAST in or out
you can also use :
storm-control {broadcast | multicast | unicast} level percentage
I have tried nexus 9K
check if this works on your device
switch(config)# interface ethernet 1/2
switch(config-if)# switchport block multicast
12-04-2020 02:40 AM
Hello BB,
thanks for your reply, i did try with acl , block and storm but didn't work, acl hadn't any match.
do you have any other suggestion?
Thanks
12-04-2020 03:17 AM
Hello,
what exacyly did you configure ?
interface ethernet 1/3
storm-control multicast level 100
should block all multicast traffic. If you configure that, what is the output of:
show interface ethernet 1/3 counters storm-control
?
12-04-2020 03:26 AM
Hi Georg,
SW1# sh int e 1/45 counters storm-control
[Action] S - Shut (Err Disable), T - Trap
--------------------------------------------------------------------------------
Port UcastSupp % McastSupp % BcastSupp % TotalSuppDiscards Action
--------------------------------------------------------------------------------
Eth1/45 100.00 100.00 100.00 0 [--]
12-04-2020 03:28 AM
you can try other 2 option suggested below ACL
12-04-2020 03:35 AM
Hi BB,
i did with your first acl example but didn't work, which ac you mean now?
12-04-2020 04:09 AM
Optios provided in the first reply :
you can also use :
Opotion 2
storm-control {broadcast | multicast | unicast} level percentage
I have tried nexus 9K
Options3 :
check if this works on your device
switch(config)# interface ethernet 1/2
switch(config-if)# switchport block multicast
12-04-2020 04:12 AM
thanks BB,
I did , but didn't work .
12-04-2020 04:26 AM
Hello,
what traffic is being generated, by what multicast application ?
12-04-2020 04:30 AM
Hi Gerorg,
DVB Transport steams , video signals.
is there any configuration with filtering that i can apply on this nexus 3k?
Thanks in advance
12-04-2020 04:37 AM
provide more information of interface config ? and some log show that device still sending Multicast to what IP address or range ?
is the device connected has any IP address ?
12-04-2020 04:42 AM
Hello BB,
here the sh run
interface Ethernet1/45
description *********L2(Multicast)*********
switchport access vlan 200
speed 1000
duplex full
12-04-2020 05:02 AM
Just to clarify - when yoy say not working, command not accepting or not working after command implemented.
what is the version of NXOS running ?
show version
show features
show interface eth1/45 capa
12-04-2020 05:08 AM
Hi BB,
not working after command implemented, here below the outputs:
Software
BIOS: version 4.0.0
NXOS: version 7.0(3)I4(7)
BIOS compile time: 12/05/2016
NXOS image file is: bootflash:///nxos.7.0.3.I4.7.bin
NXOS compile time: 6/28/2017 14:00:00 [06/28/2017 21:53:29]
Hardware
cisco Nexus3000 C3064PQ Chassis
Intel(R) Celeron(R) CPU P4505 @ 1.87GHz with 3903284 kB of memory.
Processor Board ID FOC17372DSZ
Device name: NTFRA-SW1
bootflash: 1638000 kB
usb1: 0 kB (expansion flash)
Kernel uptime is 1023 day(s), 0 hour(s), 50 minute(s), 53 second(s)
Last reset at 871694 usecs after Thu Feb 15 11:40:06 2018
Reason: Reset Requested by CLI command reload
System version: 7.0(3)I4(7)
Service:
plugin
Core Plugin, Ethernet Plugin
Active Package(s):
--------------------------------------------------------------
SW1# sh feature
Feature Name Instance State
-------------------- -------- --------
bash-shell 1 disabled
bfd 1 disabled
bgp 1 disabled
dhcp 1 disabled
eigrp 1 disabled
eigrp 2 disabled
eigrp 3 disabled
eigrp 4 disabled
hsrp_engine 1 disabled
imp 1 disabled
interface-vlan 1 enabled
isis 1 disabled
isis 2 disabled
isis 3 disabled
isis 4 disabled
isis 5 disabled
isis 6 disabled
isis 7 disabled
isis 8 disabled
isis 9 disabled
isis 10 disabled
isis 11 disabled
isis 12 disabled
isis 13 disabled
isis 14 disabled
isis 15 disabled
isis 16 disabled
lacp 1 disabled
ldp 1 disabled
lldp 1 enabled
mpls_static 1 disabled
msdp 1 disabled
nve 1 disabled
nxapi 1 disabled
of_agent 1 disabled
onep 1 disabled
ospf 1 disabled
ospf 2 disabled
ospf 3 disabled
ospf 4 disabled
ospfv3 1 disabled
ospfv3 2 disabled
ospfv3 3 disabled
ospfv3 4 disabled
pbr 1 disabled
pim 1 enabled (not-running)
private-vlan 1 disabled
privilege 1 disabled
ptp 1 disabled
rip 1 disabled
rip 2 disabled
rip 3 disabled
rip 4 disabled
scheduler 1 disabled
scpServer 1 disabled
segment-routing 1 disabled
sflow 1 disabled
sftpServer 1 disabled
sshServer 1 enabled
tacacs 1 disabled
telnetServer 1 enabled
tunnel 1 disabled
udld 1 disabled
vmtracker 1 disabled
vni 1 disabled
vnseg_vlan 1 disabled
vpc 1 enabled
vrrp 1 disabled
vrrpv3 1 disabled
vtp 1 disabled
-------------------------------------------------------
SW1# sh int e 1/45 capabilities
Ethernet1/45
Model: N3K-C3064PQ-10GX
Type (SFP capable): 1000base-X
Speed: 100,1000,10000
Duplex: full
Trunk encap. type: 802.1Q
Channel: yes
Broadcast suppression: percentage(0-100)
Flowcontrol: rx-(off/on),tx-(off/on)
Rate mode: dedicated
Port mode: Routed,Switched
QOS scheduling: rx-(8q2t),tx-(7q)
CoS rewrite: yes
ToS rewrite: yes
SPAN: yes
UDLD: yes
MDIX: no
TDR capable: no
Link Debounce: yes
Link Debounce Time: yes
FEX Fabric: yes
dot1Q-tunnel mode: yes
Pvlan Trunk capable: no
Port Group Members: none
EEE (efficient-eth): no
PFC capable: no
Buffer Boost capable: yes
Breakout capable: no
MACSEC capable: no
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide