VLAN provides over a subnetted network is that devices in different physical locations, not going back to the same router, can be on the same network. The limitation of subnetting a network with a router is that all devices on that subnet must be connected to the same switch and that switch must be connected to a port on the router.
The use of Private VLAN's defers the need for subnetting of the IP address space allowing all hosts in the same Private VLAN to share the address space.
You are in right direction. Try to configure your concept. Click following URL that will help you to solve your problem.
http://www.cisco.com/en/US/products/hw/switches/ps597/products_user_guide_chapter09186a008007edb5.html
953819
Once the host is authenticated, it can also be assigned to a particular VLAN. Depending on how precisely the network is architected, VLANs can restrict user groups to a predefined set of resources and prevent users from accessing other areas of the network.
If you want to know more please click Below URL :
http://www.cisco.com/en/US/netsol/ns466/netqa0900aecd800fdd6f.html