2.2 - Bridge Security (Access List 700)
2.2 - Bridge Security (Access List 700)
3700-BR1:
---------
access-list 700 permit <<mac address>> (sh dot11 bssid 3700-BR2)
access-list 700 deny 0000.0000.0000 ffff.ffff.ffff
3700-BR2:
---------
int dot11Radio 1
l2-filter bridge-group-acl
shut
no shut
Verification:
--------------
3700-BR1
--------
4500-2#ping 10.20.14.11
3700-BR1#ping 10.20.14.11
3700-BR1#sh access-lists
Bridge address access list 700
permit 1234.5678.9123 0000.0000.0000 (3 matches)
deny 0000.0000.0000 ffff.ffff.ffff (3 matches)
3700-BR1#
3700-BR2
--------
3700-BR2#sh access-lists
Bridge address access list 700
permit 1234.5678.9123 0000.0000.0000 (14 matches)
permit 1234.5678.9123 0000.0000.0000 (93 matches)
permit 1234.5678.9123 0000.0000.0000 (5 matches)
deny 0000.0000.0000 ffff.ffff.ffff (3 matches)
3700-BR2#