MAC based access control.

Unanswered Question
Sep 15th, 2008

Dear All,

im trying to meet some simple requirements.

1. I have a stack of 10 C3560 with 4 uplinks to my core C6500.

2. The client wants to allow predetermined list of MACs (PC) and give them roaming in any of the 10 switches.

3. Anybody else bringing personal laptops are not welcome.

4. cant add any authentication server, atleast as of now.

5. these 10 switches also have IP phones and WAPs.

have tried MAC ACLs, need to confirm what all MACs i need to allow, viz IP phones, WAP, specific switch MACs etc..

tried VACL matching a simple MAC ACL, didnt work , though working on it.

any possible solution ?


I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 4 (1 ratings)
shukla1975 Tue, 09/16/2008 - 10:35

Thanks Giuseppe,

i guess my C6500 with SXF12a does not have mac ACLs, only VACL.

I guess need to try again my MAC-ACLS on C3560 and work with them, my only fear was not block any control plane MAC which are used for STP or related switch functions.

So i need to upgrade to SXH for PACLs..

will revert


shukla1975 Tue, 09/16/2008 - 23:17

Hi All / Giuseppe,

Can I try to give static MAC in the DHCP server in C6500 so as to reserve the DHCP pool to give IPs to only the specified MAC and not to any one else.

or , i need to map MAC to IP address statically to achieve granular control.

pls do let me know


Giuseppe Larosa Wed, 09/17/2008 - 03:33

Hello Shukla,

int the DHCP server you can configure reservations so that a specific client with a specific MAC address will always get the same IP address from the pool.

Actually, I can do this on a Cisco Registrar DHCP server.

I think you can do something similar on the DHCP server on the C6500 but it can require a command for each client (at least)

Hope to help


shukla1975 Wed, 09/17/2008 - 05:58

Hi Giuseppe

yes, i read in the docs, we need to create a single DHCP host pool for single IP-MAC mappings, kinda tedious but fine.

i need to look into MAC-ACLs now.

thanks and appreciate all your writings.



This Discussion