cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
890
Views
5
Helpful
3
Replies

Block Host to Host Communications on a sub-interface

shax77
Level 1
Level 1

We have our guest network on a sub-interface and are discussing a method of preventing communications between hosts on the guest network.  Is it possible to create an access rule in that sub-interface to accomplish this?

1 Accepted Solution

Accepted Solutions

Seb Rupik
VIP Alumni
VIP Alumni

Hi there,

Communication between hosts connected to the same sub-interface will be done at Layer2, no traffic will hit the firewall and therefore it cannot be blocked.

To prevent this communication you should configure protected ports on the access layer where this VLAN is used.

 

cheers,

Seb

View solution in original post

3 Replies 3

Seb Rupik
VIP Alumni
VIP Alumni

Hi there,

Communication between hosts connected to the same sub-interface will be done at Layer2, no traffic will hit the firewall and therefore it cannot be blocked.

To prevent this communication you should configure protected ports on the access layer where this VLAN is used.

 

cheers,

Seb

Thanks for clarifying my thinking. I will pursue the options suggested here!

Hamdi Kadri
Level 1
Level 1
You can't configure this on you Firewall, instead you may think of PVLANs as a better solution on your access Switch.
Check this: https://learningnetwork.cisco.com/docs/DOC-16110
Review Cisco Networking for a $25 gift card