12-31-2013 05:33 AM - edited 03-07-2019 05:19 PM
Experts,
I'm configuring a PACL on my L2 Switch to block a user. Both of us reside on the same L2 Switch and the same VLAN. On the Switch, I conifgured this statment globally on the Switch:
mac access-list extended Deny
deny host xxxx.xxxx.xxxx any
Under my interface, I configured this statement:
mac access-group Deny in
After I did this, my computer experienced severe connectivity issues. So, I added a permit any any statement below the deny statement. Still, severe connectivity issues. I followed the configuration guide.
Did I miss anything? I assume the ACL logic is correct.
Solved! Go to Solution.
12-31-2013 06:14 AM
Thomas
Unfortunately the 3560 only supports PACLs in the inbound direction so you can't do what you want using these type of acls.
You could instead use a VACL which allows your filter traffic within the same vlan. See this link for details -
Jon
12-31-2013 05:45 AM
Thomas
I may not be understanding but your line denies all traffic from that mac address so i would expect you wouldn't be able to connect to anything ie. -
deny host xxxx.xxxx.xxxx any
assuming xxxx.xxxx.xxxx is the hosts mac address you are denying all traffic to any destination.
Adding a permit line will do nothing as it will never be matched.
Jon
12-31-2013 05:48 AM
Jon,
I may have my ACL logic wrong, but the xxxx.xxxx.xxxx is the host MAC I'm trying to deny from reaching my computer.
12-31-2013 05:57 AM
Thomas
The acl would need to applied in the outbound direction for that acl to work. That said, it depends on the switch you are using as some switches have the restriction wiith PACLs that they can only be applied in the inbound direction.
Which switch are you using ?
Jon
12-31-2013 06:04 AM
WS-C3560G-48PS-S; Version 12.2(44)SE5
12-31-2013 06:14 AM
Thomas
Unfortunately the 3560 only supports PACLs in the inbound direction so you can't do what you want using these type of acls.
You could instead use a VACL which allows your filter traffic within the same vlan. See this link for details -
Jon
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: