is this possible to do? If I want to have groups of vlans to have their own routing tables preventing the groups to route between eachother and push them to a default gateway of a firewall.
if so do you need any special hardware or software? Is an FWSM required?
Any good docs on this would be usefuly cant seem to find anything on it.
this is possible with sup720
you can use VRF lite or full featured MPLS VPN to have separate routing tables and subsets of interfaces
the difference is that in VRF lite no MPLS links are used and you need to provide dedicated logical links for each topology.
With MPLS this is not needed.
A FWSM is not required but it can completes the solution in some scenarios
a design guide
Hope to help