ibrahim A
asked on
Cisco VLAN Routing VACLs on Cisco 4507 Switch
Hi All,
I have 10 VLANs configured in my Cisco 4507 switch, Vlan 2, 3, 4 ,etc, as 192.168.1.1, 192.68.2.1 and so on, currently all VLANs can ping each others, for example VLAN 2 can ping 3,4,5, etc, I want to implement some VLAN access list to prevent VLANs to access each other, but I want VLAN 2 to be accessible by all oher VLANs, please support.
Thanks
I have 10 VLANs configured in my Cisco 4507 switch, Vlan 2, 3, 4 ,etc, as 192.168.1.1, 192.68.2.1 and so on, currently all VLANs can ping each others, for example VLAN 2 can ping 3,4,5, etc, I want to implement some VLAN access list to prevent VLANs to access each other, but I want VLAN 2 to be accessible by all oher VLANs, please support.
Thanks
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
is the switch doing routing for the VLANs or is there a router too? usually these lists are applied to interfaces or subinterfaces on routers, unless the switch functions at layer3. the lists will be applied inbound. you may need to add the statement
access-list 100 permit ip any any at the end to allow internet traffic to keep flowing.
access-list 100 permit ip any any at the end to allow internet traffic to keep flowing.
you can use VLAN access maps to the trick.
http://www.cisco.com/en/US/docs/switches/lan/catalyst4500/12.2/31sga/configuration/guide/secure.html#wp1051696
http://www.cisco.com/en/US/docs/switches/lan/catalyst4500/12.2/31sga/configuration/guide/secure.html#wp1051696
ASKER
Its layer 3 switch
Thanks
Thanks
ASKER
got it
ASKER