Stop InterVLAN routing at the edge.

Here is the scenario. 6509 core, lots of 3750 stacks, 2- 4948-10GE. Router connects to 4948.
Multiple VLANs with inter VLAN routing.
I have NO access to Router. Need to stop a group of VLAN's from communicating to/from the outside world.

Network reconfiguration in progress, but need a quick, down and dirty method to accomplish this.

Can I block these at the port on the 4948 that the router is connected to?

LVL 3
MrRudeAsked:
Who is Participating?
 
Ernie BeekConnect With a Mentor ExpertCommented:
You'll need to do that in two parts:
192.168.0.0 0.0.31.255 (covers 192.168.0.0-192.168.31.255)
And
192.168.32.0 0.0.15.255 (covers 192.168.32.0-192.168.47.255)
0
 
Ernie BeekExpertCommented:
Is there a trunk on the port? then try: switchport trunk allowed vlan 1,2,3 This way you define which VLAN's are allowed through.
0
 
MrRudeAuthor Commented:
OOPS - forgot to mention that.
Not a trunked port. That was my first thought also.
0
Cloud Class® Course: Certified Penetration Testing

This CPTE Certified Penetration Testing Engineer course covers everything you need to know about becoming a Certified Penetration Testing Engineer. Career Path: Professional roles include Ethical Hackers, Security Consultants, System Administrators, and Chief Security Officers.

 
Ernie BeekExpertCommented:
Ok.......

Acces list blocking by source address then?
0
 
Marius GunnerudSenior Systems EngineerCommented:
an ACL will take care of this apply it outbound on the interfaces connecting to the router.
0
 
MrRudeAuthor Commented:
Should I also apply it to inbound to stop incoming? I cannot figure out the inverted mask for the ip range i need blocked. Here is the range of IP's I need to block both ways. Is there a wildcard or something? Any suggestions?

192.168.0.0 - 192.168.47.255
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.