I had a quick question. When you configure "switchport protected" does this not forward traffic from other switches to this port as well as ports on the local switch?
The issue is this, we have students that like to play LAN games during school hours. Protected port seems ideal in the sense that it does not allow other protected ports from talking to each other. This seems straight forward on one switch but if you have multiple switches, will a protected port on one switch be denied from talking to a protected port on another switch?
To add on Giuseppe's point, protected port can still talk to each other via layer 3 interface if layer 3 interface is doing local proxy arp. Therefore, if you plan to use this feature, you need make sure "local proxy arp" is disabled (it should be disabled by default).
Thanks guys. I was reading some more up on it and it seems you can do this across switches but it needs to be configured on a private-vlan on the interface. And it just so happens that I have 2960's and 3560's that do not seem to support that option:(
Ahh well, is there any other option for me to help with my issue using the 2960's and 3560's ?
But the ACL's would not affect the packets until they hit the Route point and most LAN games never hit the route point. The Students are already in a separate VLAN, but they do not have a vlan for each individual student, that would be a bit tough with 700+ computers at this site.
I guess I was just looking for a easy way out and there does not seem to be. We have currently implemented client based firewalls to prevent the packets, I will see how that goes. I was hoping to do it at the switch level so the students did not try to get passed the firewall.
Hi everyone, I would like to thank you in advance for any help you can provide a newcomer like myself!
Im studying the 100-105 book by Odom and am currently on the topic of Port security. I purchased a used 2960 and I'm trying to follow a...
While deploying a number of 18xx/2802/3802 model access points (APs), which run AP-COS as their operating platform. It can be observed on some occasions that while many of their access points were able to join the fabric WLC withou...
I am going to design and build an LAN network under a tunnel underground with long distance between the switches.
I will have 2 Catalyst switches and 8 Industrial IE3000, and they will be connected with fiber.
For now I am planning on use Layer-2 s...