I have a 3560X switch that I have routing turned on for and I would like to block all traffic from one specific vlan to all others. I have the following vlans:
VLAN 20 IP Address 10.2.0.14 255.255.0.0
VLAN 23 IP Address 10.23.0.1 255.255.0.0
I have ip routing turned on and I see routes.
I want to block traffic from vlan 23 to vlan 20 and I thought this would work:
access-list 101 deny ip 10.23.0.0 0.0.255.255 any
access-list 101 permit ip any any
ip access-group 101 in
I can still ping 10.2.0.14 from 10.23.0.100.