Learn how to verify if Ethernet/IP traffic is blocked on a Cisco Layer 3 switch due to an improperly configured access control list (ACL), including identifying traffic characteristics, inspecting ACLs, checking hit counters, testing traffic flow, debugging, and endpoint. Learn how to verify if Ethernet/IP traffic is blocked on a Cisco Layer 3 switch due to an improperly configured access control list (ACL), including identifying traffic characteristics, inspecting ACLs, checking hit counters, testing traffic flow, debugging, and endpoint. There is a DMP receiver on our network that is receiving messages predictably one hour a week. I believe the messages are coming from a panel on our network. I attempted to Factory reset a VVX300 and 500 and neither would pull an IP via DHCP from behind the switch, but if I connected to via an access point (ran through the same switch) the phones can pull an IP address. Both. In this article, I'll walk you through the steps to configure access profiles and profiles rules for your Cisco switch. For example, you can restrict access to SSH. You can use IP source guard (IPSG) to prevent traffic attacks if a host tries to use the IP address of its neighbor and you can enable IP source guard when DHCP snooping is enabled on an untrusted interface. We have some devices (security cameras, security keypads, backup/archival servers) that need to have internet access (IoT-style dashboards, updates, etc) but I need to restrict access to specific VLANs.