Solved

VLAN traffic on a simple layer3 cisco switch

Posted on 2013-02-06
6
324 Views
Last Modified: 2013-02-28
I have a small business switch, SF300 series from Cisco, and I would like to set it up with 2 VLANs that should have no interaction.  I will treat them as if they were 2 physically separate switches.  There will be a few PCs and servers on each VLAN and each will connect to its own router/firewall.  By default the layer3 switch wants to route all IP traffic between the 2 VLANs, what is the most straightforward way to stop all interVLAN traffic?  Thanks.
0
Comment
Question by:SIDESHOWBLAH
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
6 Comments
 
LVL 18

Expert Comment

by:Akinsd
ID: 38861536
Use access lists
0
 

Author Comment

by:SIDESHOWBLAH
ID: 38861609
That was my best guess and I can see where to setup simple ACLs in the GUI, but cannot see how to assign them to a VLAN.  There is a binding option that looks like it is for assigning ACLs to ports.  Is that the best or only method?
0
 
LVL 18

Expert Comment

by:Akinsd
ID: 38861711
Can you telnet into it or connect through the console?
0
Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 

Author Comment

by:SIDESHOWBLAH
ID: 38861788
Yes.  I even got into some limited CLI mode to assign IPs to the VLANs.
0
 

Author Comment

by:SIDESHOWBLAH
ID: 38893223
it seems that these small business devices do not support applying a access-list to a VLAN.
0
 
LVL 18

Accepted Solution

by:
Akinsd earned 500 total points
ID: 38894019
The access lists are applied to the interface. You then create allow or deny subsets you want to permit or deny on the interface
0

Featured Post

Flexible connectivity for any environment

The KE6900 series can extend and deploy computers with high definition displays across multiple stations in a variety of applications that suit any environment. Expand computer use to stations across multiple rooms with dynamic access.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
switch design question 6 47
BGP prefix and routing 3 99
Public IP Address - Subnet 4 55
VLAN Question 13 81
I see many questions here on Experts Exchange regarding switch port configurations and trunks. This article is meant for beginners in the subject to help to get basic knowledge about Virtual Local Area Network (VLAN (http://en.wikipedia.org/wiki/Vir…
This article is focussed on erradicating the confusion with slash notations. This article will help you identify and understand the purpose and use of slash notations. A deep understanding of this will help you identify networks quicker especially w…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

734 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question