Lab — Restrict Devices with a MAC-Based ACL

Branch IDF switch hardening · pseudonymous submission
SY0-701 4.1 2.5.2.1 3.2.1.8
Scenario

You are the on-call network technician for Larkmere Outfitters, a regional retailer. Customers and staff keep plugging personal streaming sticks and casting dongles into the open Ethernet jacks of the back-office IDF, where the access switch sw-idf-b2 lives. Management wants those device families kept off that switch at layer 2.

Your task is to build a MAC-based ACL on sw-idf-b2 that denies the known hardware-address ranges of those devices, bind it to every access port, and persist the change so it survives a reboot.

Switch Web Console — sw-idf-b2
admin@sw-idf-b2 · 24-port Gigabit managed

MAC-Based Access Control Lists

Create a named ACL, then add deny entries. In this console a mask byte of FF means ignore that byte (match any value); a mask byte of 00 means match that byte exactly.

Lab Tasks
    0 / 0
    tasks + questions
    Knowledge Check
    Enter a hacker name to enable submission.