cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
899
Views
0
Helpful
4
Replies

WS-C3850-12XS || internet & interanet blocking

yogesh1
Level 1
Level 1

Hi All,

 

I need to block internet & internet of one particular user so how can we block this communication i only have mac information of this user.

I have L3 switch WS-C3850-12XS so is there any kind of filtering option so we can enable it on L3 switch it self so user will not get even IP address.

On l3 switch we have all the SVI.

4 Replies 4

saif musa
Level 4
Level 4

Hi, 

you can use Class-map, Policy-map and then apply it to the designated port. see example below

class-map match any unwanted-pc's

match source-address mac aaaa.bbbb.cccc

match source-address mac nnnn.jjjj.dddd

match source-address mac oooo.llll.pppp

!

policy-map block

class unwanted-pc's

drop

!

int gi 0/1 <--------------------- designated port which the PC is connected

description "LAN Interface"

service-policy input block

 

Regrads

 

Dear Saif,

 

Can we use below command  for blocking because behind L3 there is multiple UPlink goes to access switches & i want to block for this user.

so when he reach to L3 connection will drop automatically.

So i can not map any uplink port as there is multiple uplink

mac address-table aaa:bbbc:ddd vlan x drop?

 

Dear Saif,

 

I have check this is working fine with below command.

 

mac address-table aaa:bbbc:ddd vlan x drop

Review Cisco Networking products for a $25 gift card