cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
547
Views
0
Helpful
3
Replies

How to combine MAC and IP ACL in Catalyst 3550

e.slavov
Level 1
Level 1

I wannt to permit forwarding on Catalyst 3550 only if IP address is used with specific MAC address. Something like:

permit ip x.x.x.x mac x.x.x.x.x.x any

deny ip any any

So if user changes his ip address to not be abble to use network. How to accomplish this? Thanks in advance

3 Replies 3

mibarta
Cisco Employee
Cisco Employee

MAC access lists are for non-IP traffic only and IP access lists for IP traffic only. You can't combine them. IP traffic can't be subject of MAC access list, only non-IP traffic can.

Thanks. I will try to accomplish this with static arp and some kind of IP ACL. But it will be good if in the future MAC and IP ACL can be used together.

Is this the case for the 2950's as well? The access list documentation doesn't say anything about MAC addresses being restricted to non-IP traffic that I can see.

Thanks,

Terry

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: