cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1038
Views
0
Helpful
7
Replies

RV320 IP & MAC Binding Query

tattwam01
Level 1
Level 1

Hello all,

 

I have set up IP and Mac Binding on my Cisco RV320 router.

 

What I have done is:

1. Added IP addresses with Mac IDs

2. Checked"Block MAC address on the list with wrong IP address" option.

 

If someone tries to set an unauthorised IP address, he is able to access the intranet(Why?). Is this default setting? 

I want the PC to be completely blocked from intranet as well Internet.

 

I hope my question is clear. Please let me know if anything is unclear.

Regards

Tattwam

7 Replies 7

Hello,

 

the first thing you want to do is to upgrade your firmware (latest release in the link below). If the feature works correctly, the rogue PC should have no access at all to your network.

 

1.4.2.15

 

https://software.cisco.com/download/release.html?mdfid=284005929&catid=268437899&softwareid=282465789&release=1.4.2.15&relind=AVAILABLE&rellifecycle=&reltype=latest

Hello George, 

Thanks for the reply.

 

I already have the latest version.

 

Hello,

 

I appears that there is a flaw with older versions of firmware, where the amount of MAC bindings was limited to 30, and the block feature did not work as designed. Simply upgrading the firmware doesn't resolve the issue, you need to reset the device to factory defaults, and then reinstall the latest firmware.

Can you give that a try ? 

Surprisingly I faced the issue limiting 30 users with IP and MAC binding, that's why I did factory reset and firmware update.

Hello,

 

the weird thing is that the bug related to this issue recommends to downgrade to firmware version 1.1.1.19, you might want to give that version a try...

That's really weird thing..

I will give a try soon.

Thanks

Aleksandra Dargiel
Cisco Employee
Cisco Employee

Dear All,

 

Please note one thing:

same subnet traffic is never reaching router, routing part of the device thus is never blocked.

 

when host is trying to communicate with another host it sends arp request "who has this IP address"and the respective host would responds with its mac address and session is established directly.

 

That is why router will not block or filter such a traffic.

 

I hope it makes sense.

Aleksandra