12-09-2009 10:16 PM - edited 03-04-2019 06:55 AM
hi all,
i am having one scenario
i need to create 3 vlans like
vlan1-- sales
vlan2 --- tech
vlan3-- manager
what i need is sales and tech are need to access their own vlan but manager need to access all vlans
and gateway is single.
12-09-2009 10:52 PM
Hello Cyril,
this can be done: the gateway provides inter-vlan routing.
To introduce connectivity limitations you need to deploy the appropriate ACLs.
vlan 1 -----> 10.10.10.0/24
vlan 2 ------> 10.10.20.0/24
vlan 3 ------> 10.10.30.0/24
access-list 101 permit ip 10.10.10.0 0.0.0.255 10.10.30.0 0.0.0.255
access-list 102 permit ip 10.10.20.0 0.0.0.255 10.10.30.0 0.0.0.255
int vlan 1
ip access-group 101 in
int vlan 2
ip access-group 102 in
note:
if you want to provide internet access you need modified ACLs like
access-list 111 deny ip 10.10.10.0 0.0.0.255 10.10.20.0 0.0.0.255
access-list 111 permit ip 10.10.10.0 0.0.0.255 any
access-list 112 deny ip 10.10.20.0 0.0.0.255 10.10.10.0 0.0.0.255
access-list 112 permit ip 10.10.20.0 0.0.0.255 any
to be applied in place of the previuos ones
Hope to help
Giuseppe
12-09-2009 11:08 PM
hi,
i can use same method in layer 3 switch also
12-10-2009 03:30 AM
Hello Cyril,
yes, actually I've provided example commands for a Cisco multilayer switch
the vlan x is the L3 interface associated to Vlan x (L2 broadcast domain) and they are called SVI switchted virtual interface
Hope to help
Giuseppe
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide