Solved

CISCO VLAN's Router On A Stick Method

Posted on 2011-03-23
6
494 Views
Last Modified: 2013-12-09
Hi Guys,

I have just started looking into CISCO and the first thing that I would like to achieve is VLANS. I have found all the commands to do what I want to do when I config the switch through the console port, but it seems that CISCO have changed some of the commands since one of the youtube vids I was watching.

What I want to be able to do is setup VLAN 1, 2 and 3 lets say:

I want to stop VLAN 1 and 2 talking to each other but would like them to be able to see and talk to VLAN 3.

I have managed to look up Router on a stick which is very similiar to what I am trying to achieve but most of the tutorials allow VLAN 1 and 2 to talk between each other.

I was wondering maybe if someone knew all the commands I needed to get this up and running?

Thanks in advance
0
Comment
Question by:dan4132
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
6 Comments
 
LVL 4

Accepted Solution

by:
m_walker earned 167 total points
ID: 35197679
By default all vlans will be able to see each other.  You have three choices.
1. User an external firewall and use those ACLs (could be an over kill and slow things down a little)
2. Policy Based Routing - where acls are used to allow packets to go between vlans
3. VRF and limit routing tables (and ensue you dont use you common vlan as the default gateway else the other 2 will route via the common one.

I dont have a quick example of PBR but it should be the simplest.  I generally find the PBR is slow and use a firewall (as simple linux box with ip tables was faster then my 3750E PBR setup.  My ACS firewall as faster then PBR.

VRF is good, but wont work if you need to route via the common vlan to the net.
0
 
LVL 9

Assisted Solution

by:ffleisma
ffleisma earned 167 total points
ID: 35197733
you can use access list to block traffic between VLAN 1 & VLAN 2. what cisco router are you using? and what switch? I'll be glad to help you out on the config.
0
 
LVL 3

Author Comment

by:dan4132
ID: 35197944
Hey Guys,

Thanks very much for your input. So I guess ACL's is the way forward with this.

I have:
1 x Cisco Catalyst 3550 Switch (I mainly use this one over the 2950)
1 x 2950 Switch
1 x 2621 Router

Any help would be appreciated :)

Thanks

0
 
LVL 46

Assisted Solution

by:Craig Beck
Craig Beck earned 166 total points
ID: 35202724
If you're doing router-on-a-stick just put an ACL on each interface.

Something like this (off the top of my head)...

interface fa0/0.1
encapsulation dot1q 1
ip address 192.168.1.1 255.255.255.0
ip access-class 101 in
!
interface fa0/0.2
encapsulation dot1q 2
ip address 192.168.2.1 255.255.255.0
ip access-class 101 in
!
interface fa0/0.3
encapsulation dot1q 3
ip address 192.168.3.1 255.255.255.0
ip access-class 101 in
!
access-list 101 deny ip 192.168.1.0.0.0.0.255 192.168.2.0 0.0.0.255       (Blocks access from Vlan1 to Vlan2)
access-list 101 deny ip 192.168.2.0 0.0.0.255 192.168.1.0 0.0.0.255       (Blocks access from Vlan2 to Vlan1)
access-list 101 permit ip any any                                                               (Allows everything else)
0
 
LVL 3

Author Comment

by:dan4132
ID: 35473706
Will Close
0

Featured Post

Is your NGFW recommended by NSS Labs?

Ours is! NSS Labs Next Generation Firewall Test gives the WatchGuard Firebox M4600 a "Recommended" rating! Curious where your NGFW landed on the  Security Value Map? See the map and download the full report today!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In the hope of saving someone else's sanity... About a year ago we bought a Cisco 1921 router with two ADSL/VDSL EHWIC cards to load balance local network traffic over the two broadband lines we have, but we couldn't get the routing to work consi…
In the world of WAN, QoS is a pretty important topic for most, if not all, networks. Some WAN technologies have QoS mechanisms built in, but others, such as some L2 WAN's, don't have QoS control in the provider cloud.
This Micro Tutorial will show you how to maximize your wireless card to its maximum capability. This will be demonstrated using Intel(R) Centrino(R) Wireless-N 2230 wireless card on Windows 8 operating system.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Suggested Courses

728 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question