Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Restrict Inter-VLAN routing

We have a Catalyst 3750G switch with about 10 VLANs.  Most of the VLAN's have helper IP's to a DHCP server.  We've just purchased two Cisco 2600 WAP's to include public access, and we want to connect them to their own VLAN and restrict access on some wireless devices (or some SSID's) to NOT be able to reach devices on the other VLAN's. If it's easier for now we can restrict all wireless devices to their own VLAN and internet access only. 

Is there a way to disable inter VLAN routing for one VLAN only?  I understand I will probably have to set up another DHCP server interface on that VLAN.  Also what about security and setting up a Radius server?  It would be nice to use all the features the 2600's have.

1 REPLY
Hall of Fame Super Blue

Restrict Inter-VLAN routing

Anthony

Usually to restrict inter vlan access you would use an access list (acl) on the SVIs (Switched Virtual Interface) ie. the "interface vlan " bit in your configuration.

You can allow DHCP through with an acl to your current DHCP server and then block all other traffic. But it depends on where the internet access is ie. if to get to the internet you need to go via another vlan then you would need to allow that through as well.

If internet access was in the same vlan and you created another DHCP server for that vlan then you could completely disable inter vlan routing by removing the SVI for that vlan and then the wireless clients would not be able to route to any other vlans internally.

But usually DHCP and the physical internet access are not on the same vlan as the wireless clients.

In terms of security you may be better posting that part in the Wireless forums. You can use Radius to authenticate clients but i haven't done that in a long time so i'm not really up to date on that side of things.

Jon

135
Views
0
Helpful
1
Replies
CreatePlease login to create content