Hi, I have a Cisco 4500-E, with a Supervisor 7E card installed behind an ASA 5520. The 4500 is acting as the primary gateway for dozens of subnets, which is then routed over a cross-connect network with the ASA, then out to the internet.
I am trying to do the same with our DMZ networks, having them on the 4500, with SVI's as gateways similar to the user networks, however, I'm trying to figure out the best approach to controlling traffic between them.
VACLs, router ACLs? I've read about zone-based firewall in IOS, however the 4500 doesn't seem to support this.
Any recommendations? I don't want to have 15 ACE's per router ACL as this doesn't look efficient and manageable.