Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

how to block on layer 3 switch

Please anybody give me an example to block ?

I did some test using Cisco's example but not work. I tryied

deny ip=" and deny mac=0100:5e00:0116, not work!!!

I also tried disable multicast on an interface

"switchport block multicast", but the multicast still can pass through switch ?? I using NAM at uplink switch and capture multicast from the downlink switch (which I alreday disabled multicast on interface). Need Help .

Thanks lots

New Member

Re: how to block on layer 3 switch

To block multicast address like, you need to block the destination address, not the source address. Access-list deny ip only block packets originated from the specified address. You should use extended access-list to make it work. For example:

access-list deny ip any

Hope this helps,


New Member

Re: how to block on layer 3 switch

Thanks. I did use destination= and the MAC, sorry I do not make my question clear.

It looks like multicast automatically feed to all of the vlan on a switch, I need to apply the ACL to all vlans??

New Member

Re: how to block on layer 3 switch


Per Cisco document, "Any switch port can belong to a VLAN, and unicast, broadcast, and multicast packets are forwarded and flooded only to end stations in the VLAN." Therefore, instead of flooding traffic to all vlans on a switch for multicast traffic, the switch only flood the port(s) belong to the same vlan. Thus, you don't need to apply the ACL to all vlans.



CreatePlease login to create content