MACLOCK is one way to do it but it has a lot of other effects that you may be after....and in the end it does not actually block any MAC addresses. The way I have handled this is to create a "Black Hole" VLAN -- in my case I use 999 -- to nowhere an...