Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Deny access by IP.

Is there a method of preventing a device with an IP address of 172.25.*.1 (* = any number) from being allowed on the network? The problem I am facing is the end user incorrectly configuring a device and using the .1 gateway address. We run DHCP and have multiple vlans. Our 'edge' switches are 3500XL, 2950 and 2960's.

I have thought about 802.1x but then all the devices must run a suplicant/client in order to connect and some devices are not capable of doing this.

The ideal solution would be the ability to detect the fraudulant gateway address on the edge port and disable the port.

2 REPLIES
New Member

Re: Deny access by IP.

You need to have L3 deivce for doing so. ACLs can be implemented on the interfaces which can block any ip address and any protocol.

New Member

Re: Deny access by IP.

That is what I thought, but didn't know if I was missing some hidden trick that exists.

156
Views
4
Helpful
2
Replies
CreatePlease login to create content