Solved

Cisco 3560 Switch - Disable Routing Between two VLANs

Posted on 2010-11-17
11
1,433 Views
Last Modified: 2012-05-10
Need to prevent communication between VLAN 2 and VLAN3.  Both need to be able to route out through VLAN 1.

Current IP route statement is 0.0.0.0 0.0.0.0 10.30.1.1

Network 1: 10.30.1.0/24  (VLAN 1)
Network 2: 10.30.10.0/24  (VLAN 2)
Network 3: 10.30.20.0/24  (VLAN 3)

How do I disable routing between VLAN 2 and VLAN 3?  Please provide commands.



0
Comment
Question by:ohmErnie
  • 5
  • 4
  • 2
11 Comments
 
LVL 34

Accepted Solution

by:
Istvan Kalmar earned 250 total points
ID: 34159572
Hi,

you need:
int vlan 2
 ip access-group 101 in
access-list 101 deny ip 10.20.10.0 0.0.0.255 10.30.20.0 0.0.0.255
access-list 101 permit ip any any
0
 
LVL 34

Expert Comment

by:Istvan Kalmar
ID: 34159578
sorry this acl need for you:

access-list 101 deny ip 10.30.10.0 0.0.0.255 10.30.20.0 0.0.0.255
access-list 101 permit ip any any
0
 
LVL 7

Assisted Solution

by:joelvp
joelvp earned 250 total points
ID: 34159582
conf t
ip access-list e DENYVLAN3
deny ip any 10.30.20.0 255.255.255.0
permit ip any any

ip access-list e DENYVLAN2
deny ip any 10.30.10.0 255.255.255.0
permit ip any any

int vlan2
ip access-group DENYVLAN3 in

int vlan3
ip access-group DENYVLAN2 in


0
 
LVL 7

Expert Comment

by:joelvp
ID: 34159593
Sorry, mine is wrong
0
 
LVL 7

Expert Comment

by:joelvp
ID: 34159612
this is what it should have been (but ikalmar already gave the right coding):
conf t
ip access-list e DENYVLAN3
deny ip any 10.30.20.0 0.0.0.255
permit ip any any

ip access-list e DENYVLAN2
deny ip any 10.30.10.0 0.0.0.255
permit ip any any

int vlan2
ip access-group DENYVLAN3 in

int vlan3
ip access-group DENYVLAN2 in

0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 
LVL 1

Author Comment

by:ohmErnie
ID: 34159800
How would I change this to a permit only?  Say I only want the network x.x.x.x to have access to 10.30.20.0/24 and deny everything else.
0
 
LVL 34

Expert Comment

by:Istvan Kalmar
ID: 34159828
access-list 102 permit ip x.x.x.0 0.0.0.255 10.30.20.0 0.0.0.255
access-list 102 deny ip any any
0
 
LVL 7

Expert Comment

by:joelvp
ID: 34159868
the line
access-list 102 deny ip any any
is not needed as it is implicit

and you would need to code also:
int vlan3
ip access-group 102 out
0
 
LVL 1

Author Comment

by:ohmErnie
ID: 34166129
If I have two 3560g switches connected via a SFP GB Module, do I need to create this list on both switches?
0
 
LVL 7

Expert Comment

by:joelvp
ID: 34170708
On which of the switches are the vlan interfaces defined? Or are you using HSRP? In the latter case you would have to do the job on both switches, otherwise the switch on which the interfaces are defined is sufficient.
0
 
LVL 34

Expert Comment

by:Istvan Kalmar
ID: 34171160
please show booth switches config..

0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Short answer to this question: there is no effective WiFi manager in iOS devices as seen in Windows WiFi or Macbook OSx WiFi management, but this article will try and provide some amicable solutions to better suite your needs.
Meet the world's only “Transparent Cloud™” from Superb Internet Corporation. Now, you can experience firsthand a cloud platform that consistently outperforms Amazon Web Services (AWS), IBM’s Softlayer, and Microsoft’s Azure when it comes to CPU and …
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…

863 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

25 Experts available now in Live!

Get 1:1 Help Now