Here's the issue. I'm trying to only allow traffic between one PC and a server. Both PC and server are connected to Layer 3 switches.
This would be simple if the PC had a static IP address. I could do a simple extended ip access list permitting only traffic between the PC and the server.
However, the catch is, the PC is on DHCP.. So as soon as it changes IP address, it will lose all connectivity to the server..
I looked into using the PC's hostname in the ACL, but as soon I enter the hostname on the switch, it translates it to the IP address in DNS, and that is what the config uses (which completely defeats the purpose).
I also tried doing a mac-address access-list, but that will not work when applying it on the IP interface the server is connected to (which also defeats the purpose).
Is there any other option here I'm not thinking of?
As long as the PC is dynamically receiving an IP address it will be difficult to restrict access. One option to consider would be to create a static assignment/reservation in DHCP so that the PC uses DHCP to obtain an address and always receives the same assigned address.
Bummer, yeah I was kind of afraid of that. I'm trying to avoid making any changes to DHCP etc. as around here, that is a process that can take weeks or even months to go through. But it may be the only choice, unless I simply setup a static IP on the client PC. However, this would cause another issue if the user wants to check the server from home over VPN, since he'd then be on a different IP..
Cisco ACL's are great, but there's always a catch with them.. Thanks for the reply.
Cisco DNA Center
What's new in Cisco DNA Center 2.1.2
Cisco DNA Center 2.1.2.x Features and Capabilities
Cisco DNA Center -Intent Based Networki...
A major international airport is looking to build a cutting-edge new terminal, designed to run 24/7 with no interruptions. With the airport always on round the clock, a critical component required to support this is the surveillance infrastructure, which ...
Dear expert,I am facing an issue which you may come across before. Grateful if you would teach me how to do it.I have a Cisco WS-C3650-24TS switch in MZ which I would like to configure so that on the GigabitEthernet1 / 0/1 portis configured with VLAN 100,...
Hi AllWe are looking at some new switches for our top of racks in our DC.We have looked at the 9300 series UX models with the big buffers which is classed as a high scale model.I have tried to look at some Nexus models for top of rack, but there appears t...