How to stop Cisco 1721 from automatically routing between Vlans

I have a Cisco 1721 with a 10bt WIC in it.

I have trunking configured on the fa0 interface and PAT configured on the e0 interface.  I have 2 vlans trunked with dot1q to the fa0 interface

Vlan1: 192.168.20.0/24
Vlan2: 192.168.100.0/24

PAT/DHCP are enabled to serve both vlans.

My question is, how do i prevent Vlan1 from pinging/accessing Vlan2 and vice versa?

Seeing as how both vlans are in my connected routes in show ip route, the router just assumes it should route to them, but I want them segmented, yet still able to access the internet through e0

Thanks.
LVL 5
ProbityAsked:
Who is Participating?
 
JFrederick29Connect With a Mentor Commented:
Use an access-list instead:

ip access-list extended 150
deny ip 192.168.20.0 0.0.0.255 192.168.100.0 0.0.0.255
deny ip 192.168.100.0 0.0.0.255 192.168.20.0 0.0.0.255
permit ip any any

int vlan1
ip access-group 150 in

int vlan2
ip access-group 150 in
0
 
that1guy15Commented:
Apply an ACL to both sub interfaces that block traffic from the other vlan.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.