Stop InterVLAN routing at the edge.

Here is the scenario. 6509 core, lots of 3750 stacks, 2- 4948-10GE. Router connects to 4948.
Multiple VLANs with inter VLAN routing.
I have NO access to Router. Need to stop a group of VLAN's from communicating to/from the outside world.

Network reconfiguration in progress, but need a quick, down and dirty method to accomplish this.

Can I block these at the port on the 4948 that the router is connected to?

Who is Participating?
Ernie BeekConnect With a Mentor ExpertCommented:
You'll need to do that in two parts: (covers
And (covers
Ernie BeekExpertCommented:
Is there a trunk on the port? then try: switchport trunk allowed vlan 1,2,3 This way you define which VLAN's are allowed through.
MrRudeAuthor Commented:
OOPS - forgot to mention that.
Not a trunked port. That was my first thought also.
Cloud Class® Course: Certified Penetration Testing

This CPTE Certified Penetration Testing Engineer course covers everything you need to know about becoming a Certified Penetration Testing Engineer. Career Path: Professional roles include Ethical Hackers, Security Consultants, System Administrators, and Chief Security Officers.

Ernie BeekExpertCommented:

Acces list blocking by source address then?
Marius GunnerudSenior Systems EngineerCommented:
an ACL will take care of this apply it outbound on the interfaces connecting to the router.
MrRudeAuthor Commented:
Should I also apply it to inbound to stop incoming? I cannot figure out the inverted mask for the ip range i need blocked. Here is the range of IP's I need to block both ways. Is there a wildcard or something? Any suggestions? -
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.