03-30-2019 01:19 AM - edited 03-30-2019 01:30 AM
Hi,
If I have a network consists of one core switch (L3) with the IP address, say 1.2.3.4, and several edge switches (L2), all of which are Cisco switches, and I got a report saying that the user with IP address, say 1.2.3.5 (and 1.2.3.4 is the gateway of it), is doing something bad. Now I want to track this user's physical location (e.g. on port 1 of edge switch A) so that I can do something about it (maybe sending a warning). What would be the most efficient way to do it?
Solved! Go to Solution.
03-30-2019 01:31 AM
Hi,
Try this:
Run below command on the Core Switch:
show arp 1.2.3.4
Switch#show arp 1.2.3.4 Protocol Address Age (min) Hardware Addr Type Interface Internet 1.2.3.4 0 080a.20a1.0b50 ARPA Vlan10
Copy the Hardware address from the output:
Run below command:
traceroute mac <source MAC address> <Destination MAC address>
here source mac-address you can keep as your machine address and Destination will be "080a.20a1.0b50" (mac address of IP address 1.2.3.4)
You will get the details.
03-30-2019 01:31 AM
Hi,
Try this:
Run below command on the Core Switch:
show arp 1.2.3.4
Switch#show arp 1.2.3.4 Protocol Address Age (min) Hardware Addr Type Interface Internet 1.2.3.4 0 080a.20a1.0b50 ARPA Vlan10
Copy the Hardware address from the output:
Run below command:
traceroute mac <source MAC address> <Destination MAC address>
here source mac-address you can keep as your machine address and Destination will be "080a.20a1.0b50" (mac address of IP address 1.2.3.4)
You will get the details.
03-30-2019 03:40 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide