I am configuring a Cisco 881, and am interested in restricting individual ports on the LAN (FastEthernet 0-3). I would like to be able to limit the IP addresses that someone can use based on which port they are connected to.
This way IP ACLs in another location can be used to determine whether the user was physically connected using the correct cable before the TCP connection is established.
Best Answer
If you create one VLAN per physical switch port (the 881 seems to support up to 8 VLANs), you can give each VLAN a separate ip subnet. For example:
i.e. if a connection is made from
192.168.2.65
you will know it connected throughVLAN 102
and interfacef2
.The syntax for assigning VLANs to interfaces is described here and seems to be:
The syntax for assigning an ip address to a VLAN interface (i.e. the default gateway address for the clients) is seen throughout the configuration guide and seems to be in configured form:
More info on VLANs can be found here and on subnetting here.