cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
476
Views
0
Helpful
6
Replies

access restriction

kolawole1
Level 1
Level 1

Hello,

I have a cisco 4507 CORE switch on which i want to implement routing and vlans through vtp.I Have the 3750 distribution switch (connected to the core) on which there are several vlans.

How can i prevent the vlans from talking to each other ?

I know of port protection but since there is a layer 3 device it will not work.

As of private vlans they only work in vtp transparent mode.

Since i am using dhcp i can not use vlan access map.

I can not use the switchport allowed vlan since they are on the same switch.

Any idea will be great

1 Accepted Solution

Accepted Solutions

Okay, your best bet is to use private vlans. Yes you will need transparent mode but with only 5 vlans i'm not sure that is really such an issue.

If you really want to stop every user talking to every other user within the same vlan you may want to ask why this is the case ie. you may want to reconsider some of the design setup.

Jon

View solution in original post

6 Replies 6

Jon Marshall
Hall of Fame
Hall of Fame

Not entirely sure i understand what you are asking.

If you want to restrict traffic between vlans then use normal L3 access-lists and apply them to the L3 vlan interfaces.

If this is not what you need could you clarify ?

Jon

Hi,

Users are in the same network 172.16.10.0 /24.

Thanks

From your original post -

"How can i prevent the vlans from talking to each other ?"

From this post -

"Users are in the same network 172.16.10.0 /24"

So could you clarify exactly what you want. You mention vlans on the 4500 and on the 3750, how are they related ??. Is the 3750 switch doing inter-vlan routing as well as the core ?

People here are more than happy to help you but we need the relevant information.

Jon

Hi,

5 vlans will be implemented on the 4500 switch and ip routing will be enabled on it.No user is connected to the 4500 but only servers.Inter-vlan routing will not be implemented on the 3750 switch.The 3750 will learn vlans through vtp.Users on the same vlan share the same ip address space, but i do not want them to communicate with each other but they should be able to access the server vlan on the switch.

Okay, your best bet is to use private vlans. Yes you will need transparent mode but with only 5 vlans i'm not sure that is really such an issue.

If you really want to stop every user talking to every other user within the same vlan you may want to ask why this is the case ie. you may want to reconsider some of the design setup.

Jon

Which design do you suggest in this case?

A switch in transparent mode can it learn and send vlan information from vtp server as a client would do ?

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card