02-18-2007 10:09 PM - edited 03-05-2019 02:25 PM
Hi,
I need to configure an access-list that will permit a workstation to browse specific website only and will deny all traffic.
The router is configured as the dhcp server. I will create an ip-to-macaddr reserveration for that workstation.
What I need to do is to block the workstation if the mac-address is not corresponding to a specific ip address because he might configure a static ip address that will give him access to all resources.
please help. thanks.
02-21-2007 04:05 PM
To prevent from static IP address, you should use DHCP snooping including ARP inspection.
02-21-2007 04:13 PM
Or use port security and hard code the MAC address you know is the "official" station MAC address. You can configure port security to shutdown the port if the MAC address changes.
And as the last submitee mention IP DHCP SNOOPING is another good layer.
Then an ACL on the router and bam!!!!
Security Soup!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide