I've run into a problem which I'm not sure of how (if possible) to configure.
I have been asked to tighten up some routing / ACL rules on a Catalyst 3560 to only allow authorised computers access to a protected LAN. The inside/protected LAN is vlan1 and uses 192.168.253.0/24 addressing. The outside LAN is vlan2 and is connected to our corporate network on their 10.0.1.0/24, which also has at least one router and multiple vlans.
The first problem is that we have three computers which are sitting on the corporate network which require access to the protected LAN, two have static IPs on the 10.0.1.0/24 network while the other uses dhcp and has been given an address on 10.0.5.0/24 corporate vlan. This third computer currently accesses the protected LAN via a corporate router (to get to the 10.0.1.0/24 network) and then my 3560 (to get to the 192.168.253.0/24 network).
I've tried placing a MAC access-list inbound on the interface connected to the 10.0.1.0/24 network, which works great for blocking any unwanted corporate machines sitting on said network. However any corporate computer sitting on any other vlan, like 10.0.2.0/24 still has full connectivity.
To add to this mess I've been asked to not bother with our corporate IT with requesting any configs from them or asking for a static IP on the third corporate machine mentioned. (I've stated that I may have to request that they provide a static IP on the 10.0.1.0/24 network for this machine but said I would investigate first.)
THE QUESTIONS:
1. Is it possible to MAC filter computers that access my 3560 through another router?
2. Is it possible to combine MAC and IP access-lists in an AND or an OR fashion in the same direction on the same interface?
3. Does anyone have any suggestions regarding my overall problem as described above?
Thanks,
vbahuse
I have been asked to tighten up some routing / ACL rules on a Catalyst 3560 to only allow authorised computers access to a protected LAN. The inside/protected LAN is vlan1 and uses 192.168.253.0/24 addressing. The outside LAN is vlan2 and is connected to our corporate network on their 10.0.1.0/24, which also has at least one router and multiple vlans.
The first problem is that we have three computers which are sitting on the corporate network which require access to the protected LAN, two have static IPs on the 10.0.1.0/24 network while the other uses dhcp and has been given an address on 10.0.5.0/24 corporate vlan. This third computer currently accesses the protected LAN via a corporate router (to get to the 10.0.1.0/24 network) and then my 3560 (to get to the 192.168.253.0/24 network).
I've tried placing a MAC access-list inbound on the interface connected to the 10.0.1.0/24 network, which works great for blocking any unwanted corporate machines sitting on said network. However any corporate computer sitting on any other vlan, like 10.0.2.0/24 still has full connectivity.
To add to this mess I've been asked to not bother with our corporate IT with requesting any configs from them or asking for a static IP on the third corporate machine mentioned. (I've stated that I may have to request that they provide a static IP on the 10.0.1.0/24 network for this machine but said I would investigate first.)
THE QUESTIONS:
1. Is it possible to MAC filter computers that access my 3560 through another router?
2. Is it possible to combine MAC and IP access-lists in an AND or an OR fashion in the same direction on the same interface?
3. Does anyone have any suggestions regarding my overall problem as described above?
Thanks,
vbahuse