Today we decided we would have a crack at preventing kids from playing games against each other over the network. We did some research and discovered whats called MAC ACLs or Media Access Control (address) Access Control Lists. Using the MAC ACLs we can restrict traffic from just the desktops to the VLAN gateway and thus preventing communication between the desktops themselves. Now this can only be applied to the desktop VLAN as other devices such as print servers and Wireless Access points need to communicate with many devices besides the VLAN gateway. Unfortunately we are yet to be able to prevent wireless users from playing games against each other but the biggest offenders come from desktop users so we can consider this successful for the time being.
Because of this type of restriction we decided to implement it on a trial basis and only implement it on the local switches so we can monitor it effects on day to day usage of the PCs (if any). If we are convinced that it will not provide any issues to the desktop users we will implement MAC ACLs across the entire switching infrastructure at Dromana SC.