I need help building ACLs to control traffic between VLANs ...
Posted on 2008-06-16
I'm completely new to building ACLs on a Catalyst switch. That said, I have experience doing so on the PIX platform so I have some understanding of concepts, etc.
Here is what I'm trying to do:
There are two VLANs in questions -
the first can be considered the "main" vlan (id = 2, subnet 192.168.50.x) where all the clients and some servers live.
the second can be considered the "web" vlan (id = 3, subnet 192.168.51.x) where all our web servers live.
Right now, since IP Routing is enabled on the switch, these two VLANs can talk to each other. I need to be able to limit this like so:
No one from the Main vlan should be able to talk to anyone in the Web vlan unless it's FTP or RDP.
No one from the Web vlan should be able to talk to anyone in Main vlan except our DB server on port 1433 only.
Does that make sense? Many thanks for any help you folks can provide ...