Blocking internet access to 1 vlan

in CCNA & CCENT
Lets say that theres an organisation which uses one Cisco 4507 layer 3 switch with separate VLANs for every block. Eacn block has 2 Cisco 2950 switches, separate VLAN and full access to internet. Some servers are in a separate VLAN.
Now we need to create a new VLAN for some users (new switch). We need to block internet access, but users should be able to access atleast one server (say ip 172.17.17.4)
Can anybody give an idea how to go on with this? Commands used ?
Now we need to create a new VLAN for some users (new switch). We need to block internet access, but users should be able to access atleast one server (say ip 172.17.17.4)
Can anybody give an idea how to go on with this? Commands used ?
Comments
snake eyes,
What is the physical topology of:
Let me try explaining.
There is one leased line for internet that is connected to router. After that there is a Pix Firewall and a Layer 3 4507 Switch. After that there are different departments in different buildings with a single VLAN for each building. Each VLAN spans on 2 switches (2950).
Some servers including a SQUID Proxy,DHCP, PDC, DNS, Web and Mail are placed in a separate VLAN.
Every PC in the network obtains IP from DHCP server and can access internet.
Now there is a new block coming up in which some PCs need to have only local networking and permissions to access a couple of servers.Internet access is to be blocked.
Thats what I am wondering about. Its possible to block internet access using Proxy for that subnet, but can it be done in switch?
And what are the commands used?
If that doesn't make any sense then you shouldn't be playing with a production box, seriously. Try it in a lab.