Security ports SG 300 - 52-2 Mac addresses on Port 1

Hello

I have a 300-52 52-Port Gigabit Managed Switch Cisco SG. On the switch, I have two ports that are connected to the vlan comments.

Now, I want to activate the safety of port on both ports. Is it possible to allow two addresses on a port?

This is because there are two users who use this two ports. But the organizers can't users use the same all the time.

Thank you and best regards,

Dominique

Hi Dominique, to add to the post of Christopher, if you wait 2 addresses on a port, but these 2 connections can connect to a different port, you can configure security of the static ports or dynamic for these ports.

Here are 2 documents to help you.

https://supportforums.Cisco.com/docs/doc-27720

https://supportforums.Cisco.com/docs/doc-27753

If you choose to use static MAC entries you can duplicate entries for the different interfaces.

In addition, as an alternative, if you know the IP address and MAC address you can use dynamic arp inspection and achieve similar results much more strictly.

-Tom
Please mark replied messages useful

Tags: Cisco Support

Similar Questions

  • How can I determine the MACaddress of the Gen 4 Apple TV so that I can connect to my network. Must register on the router MAC address to connect to the internet.

    Security on my network requires that the MAC address of the device must be registered on router or I can't connect to the internet. Does not use a password based security configuration. How to find MAC address before the introduction of Apple TV?

    Contact your ISP

  • Problem with security of the ports and disabled learning MAC addresses?

    Hello

    Is there a problem, or incompatibility, if you configure the port-security on "n" ports that belong to X vlan and also disable mac-address-table of learning on this vlan?

    Someone did he do reference, links or PDFs on this problem?

    Thank you very much

    Best regards.

    Hi Javier,

    As I showed above, the combination is valid. I did not all static entries in the security of the ports, but all entries learned through port security will be shown as static on the show see the mac address table. All dynamic learning is disabled.

    I don't know what kind of security problem, that you try to resolve, but the configuration is valid.

    Daniel Dib
    CCIE #37149

    Please evaluate the useful messages.

  • Port MAC address Dell 6224 Switch

    Y at - it a command to find ports a 6224 switch MAC address? I am desperately looking for it yesterday... Thanks in advance!

    You can use the following command to view MAC learned on an interface # show bridge address-table address.

    You can also use the technology to see the order #, collect a lot of information about the switch.

    Can you give us more information about the task, you are trying to reach?

  • SG500 showing the same MAC address on more than one port?

    My ISP has been help me solve a problem that we had with an interaction between our SG500 battery on HP customer premises equipment.

    I have the stack of SG500 divided into two VIRTUAL LANs. 8-port VLAN11 and the rest on VLAN1. Both are of VLAN native, not marked so they will carry only the traffic for their own VLAN with no mixing. I also route between these VLANs on the stack.

    VLAN11 switch ip: 10.76.20.20

    IP switch VLAN1: 10.1.1.1

    I took a port for each VLAN and plugged into the HP PSI switch, where he adapt VLANS separated which then connect to a remote data center through an MPLS.

    Here's the question: the SG500 seems to have mac address base on two HP PSI switch ports. This disrupts the HP switch, and I end up having packets to fall into a black hole. This is the output of the switch from HP showing mac based battery SG500 goods between ports in seconds:

    HP # display the address mac 8843e1-af7085

    Status and counters - Address-Table - 8843e1-af7085

    MAC address: 8843e1-af7085

    Located on the Port: 15

    HP # display the address mac 8843e1-af7085

    Status and counters - Address-Table - 8843e1-af7085

    MAC address: 8843e1-af7085
    Located on the Port: 11

    Any idea what's going on here? It's as if the SG500 uses the MAC even for both its IP addresses.

    Thank you!

    Hi Dani, the only MAC address announced by SX300/500 series should be the Mac system if you show on the SX500 mac address table, you should see the MAC even for both VLAN. I don't know why, is to confuse the HP switch unless it does not correctly between switches vlan tag.

    -Tom
    Please mark replied messages useful

  • Create an EEM to find a port (mac address)

    Hello

    I´d like to create a script to find where an IP address is associated.

    Manually I can do it by using the command "show arp | in 10.10.10.50"(IP that I'm looking for), that give me the mac address, then I use the command"Display mac ad ad 4055.39dc.f468"(mac associated with this IP address).

    GW01 #show arp | in 10.10.10.71
    Internet 10.10.10.71 0 4055.39dc.f468 ARPA Vlan10
    GW01 mac ad 4055.39dc.f468 ad #show
    Mac address table
    -------------------------------------------

    VLAN Mac Address Type Ports
    ----    -----------       --------    -----
    10 4055.39dc.f468 Po4 DYNAMICS
    Total of the Mac addresses for this criterion: 1

    Would be nice if I can run the EEM informing the IP address (example: findport 10.10.10.50) and get the final result (interface where this IP is associated with).

    How I do that? How to pass the IP address I typed EEM and after, how to get the MAC that address the first command shown?

    Thank you for all.

    The error could be related to: https://tools.cisco.com/bugsearch/bug/CSCsy89677

    If this is the case, the error message is cosmetic only.

  • A5120 switch - 48G EI didn't poster not MAC addresses connected to the port card.

    I tried to get connected mac address is displayed under political network for a switch HP A5120. model JE069A. My other switches show mac addresses, but not this model. All are in the same policy in foglight. I don't know if it related software, or something in the configuration of the switch. Any suggestion would be appreciated.

    I think that you may have about the product of network Foglight (SGR) management system.

    If so, your best bet is to post your question in the Forum of Discussion of NMS rather than the Foglight Management System forum.

    Kind regards

    Brian Wheeldon

  • Filter traffic by Mac address

    Hello

    Is it possible to configure the router cisco as switches C3800 or catalyst as C4500 or C2960 to filter traffic allowed only mac addresses? Or any other device you might suggest.

    I just want to allow these devices which belongs to the domain, which means that if a user logs on to a computer or any other devices this concerns network that I have not authorized mac addresses, he will be denied access to the network. However, none of the eligible devices may be able to use any port of the switch, which means I want to associate a Mac address authorized to a physical port on the switch.

    I hope someone could help me on this.

    Thank you

    Richard

    Hi Richard,

    on the 4500, you can do this by creating a mac access list:

    http://www.Cisco.com/en/us/docs/switches/LAN/catalyst4500/12.2/31sga/configuration/guide/secure.html#wp1051626

    and then use it in a map vlan:

    http://www.Cisco.com/en/us/docs/switches/LAN/catalyst4500/12.2/31sga/configuration/guide/secure.html#wp1051696

    I believe that you can not do the same thing on a 2960, but you may want to check (maybe ask or ">")

    HTH

    Herbert

  • VMware device with 2 network cards claiming the same IP address with two MAC addresses

    Hello.

    I see messages intermittent my gateway network two MAC addresses associated with a virtual machine running on a 5.5 ESXi host for the same IP address.

    The virtual machine is a MiTel 3300 controller for a VOIP system. the system is configured with two IP addresses, one on the local network and another with a public IP address in the DMZ. In the network configuration of the 3300, I assigned the address LAN IP at 00: 0C: 29:30:B2:B2 and the DMZ IP at 00: 0C: 29:30:B2:BC (Mac for network devices presented by the ESXi host virtual machine).

    On the host, I configured a vSwitch with exclusive access to two physical network adapters on the host machine. The vSwitch is configured with two machine virtual port groups, LAN and DMZ, with access to the physical network interface cards. Tab grouping of groups vSwitch port NIC, I replaced the order of failover of the switch to activate an active NETWORK card only for the Group of LAN ports and the other card NETWORK only for the DMZ port group. (I don't know how the content of the column of networks is determined. Neither is correct for the traffic on the physical switch. If these are configurable, please advise and I'll change the settings). The relevant parameters of vSwitch, groups of ports and VM are distinguished below.

    On the virtual machine itself, through the VMWare host, I assigned 00: 0C: 29:30:B2:B2 for the Group of LAN ports and 00: 0C: 29:30:B2:BC to the DMZ group port (best I can tell, anyway, since the MAC address field annoyingly obscures the last two digits of the MAC address - break if I invert the mapping) (, but all seems OK).

    The goal here is to make sure that MACs of ports vSwitch the 3300 is listening and sending always correspond to the physical ports that are VLAN Tag by the physical switch to ensure the routing. Generally speaking, it seems that what is happening but, intermittently, we cross one-way calls that suggests a problem of routing between us and our SIP trunk provider; coinciding with these incidents, I get an email along the lines of "the security in the network device has detected a conflict of IP address with two or more devices. The period of INVESTIGATION "DMZ. DMZ. DMZ. DMZ' is claimed by the following clients with MAC addresses: ' 00: 0C: 29:30:B2:B2' ' 00: 0C: 29:30:B2:BC'. »

    I did something in the configuration that would lead to this kind of collision intermittent? Have a hacked together a way to do something that could be accomplished in a way that is simpler and more reliable?

    Thanks for any idea that you can offer.

    Kind regards

    J.

    I probably don't fully understand your configuration, but it seems that you are not interested in using the collection of NETWORK adapters in the virtual switch of the VM MiTel 3300.

    If it is correct, why not create two virtual switches, each with a group of port (LAN and DMZ) unique and with a separate connection of (vmnic2 and vmnic1)?

    In general, collection of NETWORK adapters may be used to share traffic between uplinks and ensure that if one of the uplinks connect fails, a virtual machine still has access to the network.

  • How can I print a list of MAC addresses in the Airport utility?

    Hi-

    In our House, security Wi - Fi is obtained by listing the MAC addresses of machines allowed in our airports.  Make a list of these addresses used to be as simple as make a screenshot of the table in the Airport utility.

    Now, with MacOS 10.11.3 and Airport 6.3.6, the table in the network utility > Timed Access Control... > Wireless Clients no longer mentions the MAC addresses.  You can view them one at a time, but you cannot display them all at once.

    Is there a way - possibly with Terminal commands, or perhaps AppleScript - to display the names of the guests from the airport and MAC addresses in a kind of list?

    -Gil

    Apple has closed all utility of its utility... so now, it's the bare minimum and nothing more.

    You can buy tools of third-party network, inet, fing for your iOS devices and find all attached devices.

    Or you can buy a router to another provider and keep the most convenient airport for WAP than this OK functions.

    You can also export the configuration file... search in a text editor and remove MAC addresses... but there is nothing that even comes close to what decent average routers made nowadays.

  • MAC address and P1102W

    This is my first post here.  I just bought a new P1102w printer.  I put it up to use USB.  Now I want to use wireless, but I use a MAC filter through my router.  I think I found the MAC address of the printer.  He was under the hardware address and 12 characters.  I entered in my router.  Now how I swtch USB wireless?  I tried to read the manual but couldn't find it.  I did unplug the USB cable and press the wireless button, but nothing happened.  I tried to print a page but nothing printed.   Any help would be appreciated.  Thank you

    First of all, MAC filtering is not an effective security measure, and it makes your difficult to manage network.  Read more about it here.

    Start by unplugging the USB cable between the printer and the PC.  If you use Windows: start > all programs > Hewlett-Packard > [your printer model] > add a device.  When he asks, choose a network device and follow the instructions.

    If this does not work, download the latest version of the software for your printer from the "Support & drivers" link at the top of this page.

  • Find the MAC address of the host remotely logged on to a domain

    Hello

    I work in an environment where we use the thin client (Sun ray DTU) to connect to sessions. The sessions are communicated through solaris servers, and windows servers. Explain further, the thin client connects user to the layers of solaris that connects to windows to allow the user a session window. Window servers are in a private domain. I work as a security consultant in the business and use a management software log for surveillance of newspapers. I collect the windows logs via the software (Application, security, installation, System) agent. My question is, HOW do I GET the MAC ADDRESS OF THE THIN CLIENTS? I have the IP address, username etc but not the mac address of the workstation. However - the TASK MANAGER and REMOTE DESKTOP SERVICES MANAGER give the MAC address in the CLIENT NAME. I raised the level of the event log to ' 5 "(through registry), enabled all policies audit with categories and subcategories as well but always without success." " I am using Windows Server 2008 R2 Enterprise edition.

    Hello

    Post your question in the TechNet Server Forums, as your question kindly is beyond the scope of these Forums.

    http://social.technet.Microsoft.com/forums/WindowsServer/en-us/home?category=WindowsServer

    See you soon.

  • I do not understand this step "we can assume any MAC address we want by finding the key that controls the NIC we want to change.

    Hello
    anyone ever did in Winxp with success. I do not understand this step

    «We can assume that any MAC address, we want by finding the key that controls the NIC we want change, put in a value chain called "NetworkAddress" and affecting the MAC address we want to use formatted as a hexadecimal 12-digit number (example: 000000000001).»

    It is a part of the "Windows 2000/XP/Vista: The Hard Way.

    from this link
    http://www.irongeek.com/i.php?page=security/changemac

    Concerning

    original title: change MAC address

    Hello

    I suggest to refer to this thread and follow the steps in this thread and check if that helps:

    http://social.technet.Microsoft.com/forums/en/w7itpronetworking/thread/697bf48c-A226-4315-8875-2bbeddf16db2

    The steps in this link are for Windows 7 and they are valid for Windows XP.

    It will be useful.

  • Why is the MAC address Clone?

    When I disabled it Clone MAC address I lost access to the internet.

    Does anyone know why MAC address Clone is necessary and what it does?

    Clone MAC address changes the MAC address of the router on the internet port.

    You can use the function of the cloning MAC address to clone the MAC address of a computer if you used before your computer directly to the modem.

    Some ISPS (especially cable ISPS) only the customers to have an active internet connection at any time. To do this, check the MAC address, that is, they remember the MAC address that accessible line via the modem and lock the connection to this MAC address.

    If you test your internet connection directly with your PC first and then connect the router the router can not get an internet connection because the row is locked to the PC's MAC address. Now if clone you the address MAC from the PC on the router the router "pretended" to be PC and the ISP will accept traffic again.

    Usually, simply reset or turn on the modem to reset the lock again. Sometimes, you have to turn off the modem for a couple of hours (for example, through the night) after a few hours of inactivity the ISP removes the lock again. Sometimes call the ISP to remove the lock, but it's not very often.

    So basically, generally useless clone MAC address at all because you could accomplish the same thing by resetting the modem or it turned off for a few minutes. If you connect the router to the modem, ISP learns the MAC address of the router and it gets working internet connection. (Of course remember, that once a computer directly connected to the modem would not get active internet connection unless you change the MAC address of the computer to the MAC address of the router).

    But the function is useful if you do not want to. You simply set the MAC address of the connected device before, and you get a working internet connection.

  • Disable broadcast SSID and MAC address turn on filtering on WAG320N

    When disabling SSID broadcast and enabling MAC address filtering on WAG320N, my other laptop wireless disconnected.  And when you try to connect, it connects again.

    You can not hide from intruders.

    The router always sends the tag. The router is immediately detected.

    The SSID is always transferred not encrypted. He is always sent over the association. It is easy to force a re-Association. If there is a single device without wire connected to the access point it takes about a second to learn the SSID.

    Disable the SSID requires your wireless devices to search actively for the network. This means that your laptop will always try to connect to your SSID, as long as it is not connected to another network. As sending requires much more power then listen passively it drains your battery.

    And, in fact, if you are in an internet café anyone can learn your SSID in time where you go on the wireless at the moment where you associate with the network of internet café.

    In addition, it causes many problems with different wireless, as instability or similar cards.

    MAC filtering is still more useless that the MAC address is always part of any wireless transmission and it's always clear. It is extremely easy to pick up the allowed MAC addresses, and it is extremely easy to change the MAC address of a wireless card.

    New: use the real security and forget this nickname of security features.

    What you try to do is a waste of time. Of your time. It will slow down any intruder.

    See also

    http://homecommunity.Cisco.com/T5/wireless-routers/iPad-Wi-Fi-MAC-address-quot-not-a-MAC-address-quo...
    http://homecommunity.Cisco.com/T5/wireless-routers/is-my-router-effectively-secured/m-p/333945#M1752...

Maybe you are looking for

  • Device custom 3D-graphics

    Hello I tried to create a custom device allowing the display of data in 3D graphics. I created my device custom graph XY Add - found on the Web site OR in order to have the right model. But load in my workspace, error 1003 has occurred (see error.jpg

  • How to activate audio device

    HOW CAN I ACTIVATE THE AUDIO DEVICE My audio device shows disable.  How to activate it

  • .zip files not recognized in Windows 7

    When I had problems with Windows 10, I've restored Windows 7 on my HP laptop.  . Zip files are more recognized on my laptop.  Before the upgrade to Windows 10, I had the opportunity to unzip and zip files.    The extension of the .zip files is no mor

  • BlackBerry Smartphones Blackberry Curve 8330 SMS won't erase

    A friend thought it would be funny text me off color photo today and now I can't delete it. Can anyone offer an idea on what I can do about it? The delete option is FLEURIDAS, but after selecting the it, the file remains?

  • HP g60-519wm notebook pc 8 ich9 usb drvers are obsolete

    Computer starts up and displays the Message "loading drivers" after about 2 minutes, that it is said that he could not find the drivers. Lists 8 INTEL ICH9 USB and USB2 drivers it is not. Can't seem to find on the internet.