1) Выводите управляющие интерфейсы коммутаторов в отдельный влан
2) привязка по мак к IP? У вас IPoE? DHCP есть? в каком виде используется? IP-MAC-Binding используете?
http://www.dlink.ru/ru/faq/62/240.html
Для 3526:
create access_profile packet_content_mask offset_16-31 0x0 0x0 0x000000ff 0x0 offset_32-47 0x0 0x0 0xffff0000 0x0 profile_id 1
config access_profile profile_id 1 add access_id 1 packet_content_mask offset_16-31 0x0 0x0 0x00000006 0x0 offset_32-47 0x0 0x0 0x00870000 0x0 port 1 -24 deny
config access_profile profile_id 1 add access_id 2 packet_content_mask offset_16-31 0x0 0x0 0x00000011 0x0 offset_32-47 0x0 0x0 0x00890000 0x0 port 1 -24 deny
config access_profile profile_id 1 add access_id 3 packet_content_mask offset_16-31 0x0 0x0 0x00000011 0x0 offset_32-47 0x0 0x0 0x008a0000 0x0 port 1 -24 deny
config access_profile profile_id 1 add access_id 4 packet_content_mask offset_16-31 0x0 0x0 0x00000006 0x0 offset_32-47 0x0 0x0 0x008b0000 0x0 port 1 -24 deny
config access_profile profile_id 1 add access_id 5 packet_content_mask offset_16-31 0x0 0x0 0x00000006 0x0 offset_32-47 0x0 0x0 0x01710000 0x0 port 1 -24 deny
config access_profile profile_id 1 add access_id 6 packet_content_mask offset_16-31 0x0 0x0 0x00000006 0x0 offset_32-47 0x0 0x0 0x01bd0000 0x0 port 1 -24 deny
config access_profile profile_id 1 add access_id 7 packet_content_mask offset_16-31 0x0 0x0 0x00000006 0x0 offset_32-47 0x0 0x0 0x02510000 0x0 port 1 -24 deny
config access_profile profile_id 1 add access_id 8 packet_content_mask offset_16-31 0x0 0x0 0x00000011 0x0 offset_32-47 0x0 0x0 0x076c0000 0x0 port 1 -24 deny
config access_profile profile_id 1 add access_id 9 packet_content_mask offset_16-31 0x0 0x0 0x00000006 0x0 offset_32-47 0x0 0x0 0x0b350000 0x0 port 1 -24 deny
config access_profile profile_id 1 add access_id 10 packet_content_mask offset_16-31 0x0 0x0 0x00000006 0x0 offset_32-47 0x0 0x0 0x13880000 0x0 port 1 -24 deny
Для 3028:
create access_profile ip tcp dst_port_mask 0xffff profile_id 1
config access_profile profile_id 1 add access_id 1 ip tcp dst_port 135 port all deny
config access_profile profile_id 1 add access_id 2 ip tcp dst_port 139 port all deny
config access_profile profile_id 1 add access_id 3 ip tcp dst_port 369 port all deny
config access_profile profile_id 1 add access_id 4 ip tcp dst_port 445 port all deny
config access_profile profile_id 1 add access_id 5 ip tcp dst_port 593 port all deny
config access_profile profile_id 1 add access_id 6 ip tcp dst_port 2869 port all deny
config access_profile profile_id 1 add access_id 7 ip tcp dst_port 5000 port all deny
create access_profile ip udp dst_port_mask 0xffff profile_id 2
config access_profile profile_id 2 add access_id 1 ip udp dst_port 137 port all deny
config access_profile profile_id 2 add access_id 2 ip udp dst_port 138 port all deny
config access_profile profile_id 2 add access_id 3 ip udp dst_port 445 port all deny
config access_profile profile_id 2 add access_id 3 ip udp dst_port 1900 port all deny