12-22-2008 04:51 AM - edited 03-06-2019 03:05 AM
Hi,
Is it possible to block all communication between two switchports for a particular vlan and allow the same for all other vlans.
I want to block all traffic including ARP broadcasts for that particular vlan.
Regards,
Prakash
12-22-2008 05:11 AM
Hello Prakash,
you can think to use private vlans
private vlans could help:
additional secondary vlans of type isolated or community can be used to allow device to gateway communication only.
see
http://www.cisco.com/en/US/docs/switches/lan/catalyst6500/ios/12.2SX/configuration/guide/pvlans.html
Hope to help
Giuseppe
12-22-2008 05:17 AM
Thanks Guisseppe...
But my switchports are connected to another switch and they are configured as trunk...hence we cannot use private vlans...also there are other vlans which needs full communication even to a default gateway.
The model of the switch is 3750. I tried configuring switchport protected but it stopped all communication between the ports. Also there is no option to configure switchport protected for a particular set of vlans.
Regards,
Prakash
12-22-2008 06:36 AM
Hello Prakash,
in this case you should change your network design adding new vlans and placing some users on each of them
Hope to help
Giuseppe
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide