Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements
Webcast-Catalyst9k
New Member

Block mac-address

Hello,

I have my lan with a core swicth 3750

one port of the 3750 is connected to an ASA5510 and this ASA is connected to internet.

I want to deny internet acces of a particular PC on lan.

I want to do that based on mac-address.

here the actual config of the port of the 3750 :

interface GigabitEthernet3/0/9

description toASA5510

no switchport

ip address 192.168.96.18 255.255.255.248

srr-queue bandwidth share 10 10 60 20

srr-queue bandwidth shape  10  0  0  0

queue-set 2

mls qos trust cos

auto qos voip trust

!

why deny by "mac access-group" is not possible on this interface .. ?

I can do it also on ASA in place of 3750, but don't find how ...

Thx

Everyone's tags (2)
1 REPLY
New Member
418
Views
0
Helpful
1
Replies
CreatePlease to create content