Options

Preventing Inter-VLAN communication - Layer 3 Switches

xnxxnx Member Posts: 464 ■■■□□□□□□□
What would be the best approach to stop communication between two vlans on a 3550 L3 switch?

Would I have to use VLAN maps and or Router ACLs...? This is one of those things I've never fully understood as the CCNA level books were always based around L2 switches and ROAS..

Thanks
Getting There ...

Lab Equipment: Using Cisco CSRs and 4 Switches currently

Comments

  • Options
    aaron0011aaron0011 Member Posts: 330
    ACLs applied on the SVIs will do the trick.
  • Options
    xnxxnx Member Posts: 464 ■■■□□□□□□□
    Getting There ...

    Lab Equipment: Using Cisco CSRs and 4 Switches currently
  • Options
    tomtom1tomtom1 Member Posts: 375
    VACL's are for traffic within the VLAN. In this case, as already mentioned you need to put ACL's on the SVI.
  • Options
    xnxxnx Member Posts: 464 ■■■□□□□□□□
    Thanks, yeah I now understand how VLAN maps apply to traffic within a VLAN and can be used to prevent communication between two hosts on the same VLAN.
    Getting There ...

    Lab Equipment: Using Cisco CSRs and 4 Switches currently
  • Options
    mesho_emadmesho_emad Registered Users Posts: 4 ■□□□□□□□□□
    i want to know also
  • Options
    tomtom1tomtom1 Member Posts: 375
    mesho_emad wrote: »
    i want to know also
    The answer has been given already, what isn't clear?
  • Options
    Dieg0MDieg0M Member Posts: 861
    wrong. easiest and best way is to put them in separate VRF's
    Follow my CCDE journey at www.routingnull0.com
  • Options
    OfWolfAndManOfWolfAndMan Member Posts: 923 ■■■■□□□□□□
    #8
    wrong. easiest and best way is to put them in separate VRF's


    Agreed.
    :study:Reading: Lab Books, Ansible Documentation, Python Cookbook 2018 Goals: More Ansible/Python work for Automation, IPSpace Automation Course [X], Build Jenkins Framework for Network Automation []
  • Options
    xnxxnx Member Posts: 464 ■■■□□□□□□□
    Thanks, I guess SVI ACLs would be the best approach for a School network - it has 3560s; obviously outdated equipment?

    I'll be working on a school network and one day hope to convert one to a Staff/Students/Management VLAN setup where the VLANs are completely isolated.
    Getting There ...

    Lab Equipment: Using Cisco CSRs and 4 Switches currently
Sign In or Register to comment.