Setting up Private VLAN with only Internet Access

I would like to setup a private VLAN on our network that will only have Internet access.  This would mainly be used via wireless.  Currently we have a Cisco ASA 5505 as our firewall, several Cisco 2960 switches and a Cisco 4402 Wireless Controller.

I am familiar with setting up VLANs both on the switches and wireless controller.  But what I can't figure out is how to make that VLAN have no access to any other VLAN but still have internet access.  I am thinking ACLs, but not sure where to start, I've not really every played with them.

Thanks in Advance!
RailroadAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Don JohnstonInstructorCommented:
Probably the easiest would be to use an ACL on the 5505.  Just create an ACL that denies traffic to the local networks and a "permit any" at the end.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
RailroadAuthor Commented:
I make the ACL on our core 3560 switch by creating the ACL:

ip access-list extended Guest
 deny   ip any 192.168.0.0 0.0.255.255
 permit ip any any

and applying it to the VLAN interface:

interface Vlan51
 description Wireless Network
 ip address 192.168.51.1 255.255.255.0
 ip access-group Guest in
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Networking Hardware-Other

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.