I want to filter all input packets (IP and non-IP) from a virus PC. Because the user will change his ip address, I have to filter it out by MAC address. This function can be worked in Catalyst 3000 series but I can not find similar feature in Catalyst 3550 series. I had tried applied a named MAC extended ACL in ehternet interface and VLAN map in VLAN interface. Both of them filter out "non-IP" packets only.