Solved

Cisco Vlan routing prevention

Posted on 2012-03-12
4
402 Views
Last Modified: 2012-03-12
Hello Experts,

I am in the process of setting up Router on a stick.  A simple scenario:
1. Cisco Router (x1)
2. 1 Cisco Switch 2960
3. Other brand switches connecting to the Cisco 2960

I would like to know the following
a. I have Vlan 1, 2, 3.   What is the best way to avoid Vlan 2 and 3 from communicating, but Vlan 2 and 3 need to talk to Vlan 1.  (Should I block this via Access-list on the router) or is there an easy way to do it on the switch?

Thank you,
R
0
Comment
Question by:RandallVillalobos
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
4 Comments
 
LVL 11

Accepted Solution

by:
rowansmith earned 500 total points
ID: 37712978
You will need to use an access list on your router.

I would suggest an inbound access list on VLAN 2 which:
permit vlan2_subnet to vlan1_subnet
deny any any

Open in new window


and an inbound access list on VLAN3 which
permit vlan3_subnet to vlan1_subnet
deny any any

Open in new window


Fo the sake of completeness and security in depth you should also add a acl on VLAN1:
permit vlan1_subnet to vlan2_subnet
permit vlan1_subnet to vlan3_subnet
deny any any

Open in new window


Make sure all your access lists work on an INBOUND principle, do not let any traffic into the router unless it is destined for an allowed network.
0
 

Author Comment

by:RandallVillalobos
ID: 37712980
Thanks for help and assistance.   Can I configure these acl's on a Layer 2 Switch or are they applied on the Router?
0
 
LVL 11

Expert Comment

by:rowansmith
ID: 37713011
No this separation is Layer 3 only.  A Layer 2 switch has no visibility of the IP Addresses.

Your router is providing the IP connectivity between the VLANs.  Even if you had a Layer 3 switch, it still has a routing engine which would perform the same function that you have, (in this case), offloaded to your Cisco Router.
0
 

Author Closing Comment

by:RandallVillalobos
ID: 37713074
Appreciate your help.
0

Featured Post

Manage your data center from practically anywhere

The KN8164V features HD resolution of 1920 x 1200, FIPS 140-2 with level 1 security standards and virtual media transmissions at twice the speed. Built for reliability, the KN series provides local console and remote over IP access, ensuring 24/7 availability to all servers.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article will inform Clients about common and important expectations from the freelancers (Experts) who are looking at your Gig.
WARNING:   If you follow the instructions here, you will wipe out your VTP and VLAN configurations.  Make sure you have backed up your switch!!! I recently had some issues with a few low-end Cisco routers (RV325) and I opened a case with Cisco TA…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…
Suggested Courses

691 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question