11-20-2006 10:37 AM - edited 03-05-2019 12:56 PM
Is there a method of preventing a device with an IP address of 172.25.*.1 (* = any number) from being allowed on the network? The problem I am facing is the end user incorrectly configuring a device and using the .1 gateway address. We run DHCP and have multiple vlans. Our 'edge' switches are 3500XL, 2950 and 2960's.
I have thought about 802.1x but then all the devices must run a suplicant/client in order to connect and some devices are not capable of doing this.
The ideal solution would be the ability to detect the fraudulant gateway address on the edge port and disable the port.
11-20-2006 07:30 PM
You need to have L3 deivce for doing so. ACLs can be implemented on the interfaces which can block any ip address and any protocol.
11-20-2006 07:44 PM
That is what I thought, but didn't know if I was missing some hidden trick that exists.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide