Routing mangement

Posted on 2007-10-19
Last Modified: 2010-04-02
I have 5 VLAN segments with these IDs
all connected via 5 routers.
I need any PC into VLAN1 to see any PC into the same VALN and all ather 4 VLANs and any PC into other VLANs from 2 to 4 can not see other VLANs. Please help me for that issue.
Question by:mtarabay
    LVL 11

    Expert Comment

    Think about VLANs as a separate networks, so you need to use trivial ACLs on the routers.

    The question is
    1. What do you mean saying "PC can/cannot see other PC". Which protocol, service?
    2. Do you have a diargram how your 5 routers interconnected?

    Author Comment

    1. i mean that i want PCs into VLAN1 can ping through TCP/IP to all other VLANs while any PC into VLANs from 2 to 5 can only ping to PCs which connected with its VLAN segment (dont ping to other PCs into other VLANs).
    2. routers are connected with each other directly through fiper optic backbone while every router connected to its VLAN segment through gigaspeed copper UTP cables.
    LVL 11

    Expert Comment

    1. It will be natural that if a PC from VLAN 1 can ping another PC from VLAN 2, that PC2 will be able to ping PC1 unless you filter by type of icmp.

    2. You need to create an access lists and apply to the IP interfaces


    ip access-list extended FILTER-IN
     remark block ping requests
     deny icmp any echo
     remark block any TCP connection attempts
     deny tcp any syn
     remark permit everything alse
     permit ip any any

    apply this to IP interface of the VLAN1 router in inbound direction

    VLAN 2 and all other

    ip access-list extended FILTER-IN
     remark permit all from VLAN1 and deny everything else
     permit ip

    ip access-list extended FILTER-OUT
     remark permit all to VLAN1 and deny everything else
     permit ip

    Apply this filter to IP interfaces of routers 2-5 replacing local ip addresses in both directions.

    Author Comment

    Thanks tvman  od.
    I have tried to use static route into all routers and disable RIP with this configuration:
    VLAN1 Router:  gateway  gateway  gateway  gateway  gateway

    VLAN2 Router:  gateway  gateway

    VLAN3 Router:  gateway  gateway

    VLAN4 Router:  gateway  gateway

    VLAN5 Router:  gateway  gateway

    Did the above configuration useful into my case while every VLAN become isolated from others except VLAN1?
    LVL 11

    Accepted Solution

    I'm not really getting how did you connect your routers. Can you post configuration of VLAN1 router and a simple diagram how do you have it connected? In order to route something, the routers need to have an interface in the same network, from you config VLAN1 router has interface in 1,2,3,4,5th networks. If there is no IP, you send it to local interface by name, but it's not possible for interfaces with shared medea like ethernet.

    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    Why You Should Analyze Threat Actor TTPs

    After years of analyzing threat actor behavior, it’s become clear that at any given time there are specific tactics, techniques, and procedures (TTPs) that are particularly prevalent. By analyzing and understanding these TTPs, you can dramatically enhance your security program.

    This article is a step by step guide on how to create a basic PTP link using Ubiquiti airOS devices. This guide can be used on the following Ubiquiti AirMAX devices. Nanostation, Bullets, AirBridge, Nanobeam, NanoBridge to name a few. Please review …
    Data center, now-a-days, is referred as the home of all the advanced technologies. In-fact, most of the businesses are now establishing their entire organizational structure around the IT capabilities.
    After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
    After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

    794 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    16 Experts available now in Live!

    Get 1:1 Help Now