cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
466
Views
0
Helpful
5
Replies

Can we prevent traffic in a LAN

minh_hieu
Level 1
Level 1

Hi community,

Our customer have many VLANs which have our router subinterfaces as default gateways to the Internet. Now for security reason, our customer want to prevent traffic between hosts in a VLAN. Of course we can divide VLANs into small subnets /30 but our customer doesn't want to change it because it affects to IP of many hosts, servers in their network. Instead, they want us to set access-list in our router to prevent it. My question is if it is possible. In my opinion, it is not.

Thanks and regards,

HIeu

1 Accepted Solution
5 Replies 5

Leo Laohoo
Hall of Fame
Hall of Fame

Yes.  IT's possible. 

Agree with Loe many possible ways to prevent this.

amabdelh
Level 1
Level 1

The best way to achieve this is by using private vlans it is much better than using ACLs, easy to configure, manage, and troubleshoot

Sent from Cisco Technical Support iPhone App

Thank you all. Can you give me few ways of using ACL to do it? Because as far as I know layer 2 traffic will go directly from host to host using MAC forwarding table, not transit through our router. So how can our router apply ACL for it?

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card