Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Blocking VLAN to VLAN access via ACL's


We have a Catalyst 3550 running VTP with 5 VLANs. We would like to maintain routing on all 5 VLANS such that they all still have internet acces. Two of them we would like to block from the other 3.

For instance:

if VLAN1, 2, and 3 are associated with the subnets,, and and VLANs 4 and 5 are accociated with and

We would like to block access from VLAN 4 and 5 to everything except the gateway of last resort for internet access. Can I do this with VTP turned on using ACL's? Also how would this be implemented using the above scheme

Thank you for your time,


New Member

Re: Blocking VLAN to VLAN access via ACL's

I don't know where your problem is but I will try to answer...

You can use ACLs on the subinterfaces.

Suppose the GW of last resort is X.X.X.X. Create the following ACL for VLAN 4:

access-list 100 permit ip X.X.X.X

and the following for VLAN 5:

access-list 110 permit ip X.X.X.X

and apply them to the corresponding subinterfaces.

Is that it?

New Member

Re: Blocking VLAN to VLAN access via ACL's

Basically we have two training VLANs that they don't want to have access to the rest of the network, but still have internet access. VLAN 4 and 5 are the Training VLANs.

So this should follow this criteria?

CreatePlease login to create content