Chapter 7 Administering the Switch

Managing the MAC Address Table

If you add a unicast MAC address as a static address and configure unicast MAC address filtering, the switch either adds the MAC address as a static address or drops packets with that MAC address, depending on which command was entered last. The second command that you entered overrides the first command.

For example, if you enter the mac address-table static mac-addrvlan vlan-idinterface interface-idglobal configuration command followed by the mac address-table static mac-addrvlan vlan-iddrop command, the switch drops packets with the specified MAC address as a source or destination.

If you enter the mac address-table static mac-addrvlan vlan-iddrop global configuration command followed by the mac address-table static mac-addrvlan vlan-idinterface interface-idcommand, the switch adds the MAC address as a static address.

You enable unicast MAC address filtering and configure the switch to drop packets with a specific address by specifying the source or destination unicast MAC address and the VLAN from which it is received.

Beginning in privileged EXEC mode, follow these steps to configure the switch to drop a source or destination unicast static address:

 

Command

Purpose

Step 1

 

 

configure terminal

Enter global configuration mode.

Step 2

 

 

mac address-table static mac-addr

Enable unicast MAC address filtering and configure the switch to drop a

 

vlan vlan-iddrop

packet with the specified source or destination unicast static address.

 

 

For mac-addr, specify a source or destination unicast MAC address.

 

 

Packets with this MAC address are dropped.

 

 

For vlan-id, specify the VLAN for which the packet with the

 

 

specified MAC address is received. Valid VLAN IDs are 1 to 4094.

Step 3

 

 

end

Return to privileged EXEC mode.

Step 4

 

 

show mac address-table static

Verify your entries.

Step 5

 

 

copy running-config startup-config

(Optional) Save your entries in the configuration file.

 

 

 

To disable unicast MAC address filtering, use the no mac address-table static mac-addrvlan vlan-idglobal configuration command.

This example shows how to enable unicast MAC address filtering and to configure the switch to drop packets that have a source or destination address of c2f3.220a.12f4. When a packet is received in VLAN 4 with this MAC address as its source or destination, the packet is dropped:

Switch(config)# mac address-table static c2f3.220a.12f4 vlan 4 drop

Catalyst 3750-E and 3560-E Switch Software Configuration Guide

7-26

OL-9775-02

 

 

Page 192
Image 192
Cisco Systems 3750E manual Vlan vlan-id drop