Cisco VLAN Routing VACLs on Cisco 4507 Switch

Hi All,
 I have 10 VLANs configured in my Cisco 4507 switch, Vlan 2, 3, 4 ,etc,  as 192.168.1.1, 192.68.2.1 and so on, currently all VLANs can ping each others, for example VLAN 2 can ping 3,4,5, etc, I want to implement some VLAN access list to prevent VLANs to access each other, but I want VLAN 2 to be accessible by all oher VLANs, please support.
Thanks
LVL 1
ITMaster1979Asked:
Who is Participating?
 
ccsistaffConnect With a Mentor Commented:
The config will be done within the router used to route between VLANs.   Use access-lists to permit or deny one network to another and apply them to your router's (sub) interfaces.  

access-list 100 permit ip any 192.168.2.0 0.0.0.255
access-list 100 deny ip 192.168.1.0 0.0.0.255 192.168.3.0 0.0.0.255
<etc>
0
 
ITMaster1979Author Commented:
Ok, do I apply them in the VLAn Interface, in , or out?
0
 
ccsistaffCommented:
is the switch doing routing for the VLANs or is there a router too?  usually these lists are applied to interfaces or subinterfaces on routers, unless the switch functions at layer3.  the lists will be applied inbound.  you may need to add the statement
access-list 100 permit ip any any at the end to allow internet traffic to keep flowing.
0
Cloud Class® Course: CompTIA Healthcare IT Tech

This course will help prep you to earn the CompTIA Healthcare IT Technician certification showing that you have the knowledge and skills needed to succeed in installing, managing, and troubleshooting IT systems in medical and clinical settings.

 
ITMaster1979Author Commented:
Its layer 3 switch
Thanks
0
 
ITMaster1979Author Commented:
got it
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.