cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
267
Views
4
Helpful
7
Replies

Port security

Dears 

our CTO wants the whole company mac address to be added in a port security so that nobody outside the company can access our network, is there any alternative solution for adding all the mac addresses manually.

1 Accepted Solution

Accepted Solutions

the solution is MAB 

adding MAC is not prevent other MAC from ADD
adding MAC in port security will force only these MAC to use specific port

solution is MAB if the MAC not found in radius the access is deny 

MHM 

View solution in original post

7 Replies 7

the solution is MAB 

adding MAC is not prevent other MAC from ADD
adding MAC in port security will force only these MAC to use specific port

solution is MAB if the MAC not found in radius the access is deny 

MHM 

There  command to disable MAC learn under vlan' but I never test before' I will try it in my lab abd update you.

Thanks 

MHM

I would really appreciate it 

waiting for your feedback

Thank you 

Leo Laohoo
Hall of Fame
Hall of Fame

Randomize MAC address is going to wreck that plan.

Marvin Rhoads
Hall of Fame
Hall of Fame

Network access control (NAC) is the general term for such measures. Cisco's product that does this is Identity Services Engine (ISE).

Port-security is not a good solution for what you / your CTO wants to do,  I would suggest looking into using ISE and 802.1x.  A much better and scaleable solution.

--
Please remember to select a correct answer and rate helpful posts
Review Cisco Networking products for a $25 gift card