Disable Client Scenario

From: Rick Leclerc <leclerc_at_bradford-sw.com>
Date: Wed, 3 Sep 2003 13:38:23 -0400

Here is an actual Campus Manager scenario that some of you may not be
aware of. This is an informational posting to share actual Campus
Manager experiences with all customers so everyone is aware of the capabilities
available to them, and the requirements associated with implementing these
features... Happy Whacking to all :-)

Question:

I've been disabling some registered clients because they are sending out
a ton of ICMP traffic (I don't know why yet), but I have 2 that stay on
and show as "Violation". Their MAC addresses are not entered in the
secure port on their switches. Their names are Fred Durst and Emile Kim
and are on Englehardt_2 Fa0/6 and Fremont_2 Fa0/15 respectively. At least 10
others seem to be disabled just fine.

Answer:

The secure ports on their switches were on a different VLAN than their
ports. It seems obvious that that wouldn't work, and sure enough it
doesn't.

The issue is that the secure port defined on the switch must be on the same
VLAN as the port the user is on. So what this means is....
Each VLAN supported by a switch needs to have a secure port defined on that same switch
if you expect to disable clients (MAC addresses) for all the VLANs.
Received on Wed Sep 03 2003 - 17:45:46 EDT

This archive was generated by hypermail 2.2.0 : Tue Jan 06 2009 - 19:00:04 EST