Learn how to a build a cloud-first strategyRegister Now

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 845
  • Last Modified:

Cisco VLAN Routing VACLs on Cisco 4507 Switch

Hi All,
 I have 10 VLANs configured in my Cisco 4507 switch, Vlan 2, 3, 4 ,etc,  as 192.168.1.1, 192.68.2.1 and so on, currently all VLANs can ping each others, for example VLAN 2 can ping 3,4,5, etc, I want to implement some VLAN access list to prevent VLANs to access each other, but I want VLAN 2 to be accessible by all oher VLANs, please support.
Thanks
0
ITMaster1979
Asked:
ITMaster1979
  • 3
  • 2
1 Solution
 
ccsistaffCommented:
The config will be done within the router used to route between VLANs.   Use access-lists to permit or deny one network to another and apply them to your router's (sub) interfaces.  

access-list 100 permit ip any 192.168.2.0 0.0.0.255
access-list 100 deny ip 192.168.1.0 0.0.0.255 192.168.3.0 0.0.0.255
<etc>
0
 
ITMaster1979Author Commented:
Ok, do I apply them in the VLAn Interface, in , or out?
0
 
ccsistaffCommented:
is the switch doing routing for the VLANs or is there a router too?  usually these lists are applied to interfaces or subinterfaces on routers, unless the switch functions at layer3.  the lists will be applied inbound.  you may need to add the statement
access-list 100 permit ip any any at the end to allow internet traffic to keep flowing.
0
What does it mean to be "Always On"?

Is your cloud always on? With an Always On cloud you won't have to worry about downtime for maintenance or software application code updates, ensuring that your bottom line isn't affected.

 
ITMaster1979Author Commented:
Its layer 3 switch
Thanks
0
 
ITMaster1979Author Commented:
got it
0

Featured Post

Hire Technology Freelancers with Gigs

Work with freelancers specializing in everything from database administration to programming, who have proven themselves as experts in their field. Hire the best, collaborate easily, pay securely, and get projects done right.

  • 3
  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now