cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
618
Views
0
Helpful
4
Replies

Restrict inter-vlan traffic

Nick wfd
Level 1
Level 1

                   Hi,

I have a customer, who has the SVI's configured on the Core (4500x) and this is connected to a ASA 5525x,  there is a requirement of restricting traffic between different vlans. Please suggest on how can i use the ASA to accomplish this task.

ACLs on the Switch are not stateful and hence not considering this option, Also we are not planning to configure the GW's on the ASA since there is lot of traffic between the vlan's and this will become a bottleneck

1 Accepted Solution

Accepted Solutions

If the SVIs stayed on the switch then the traffic will never be sent to the ASA .

-Kureli

View solution in original post

4 Replies 4

Kureli Sankar
Cisco Employee
Cisco Employee

I will be discussing this issue as well in my upcoming webcast, next Tue Jan 15th. You can configure a port on the ASA as a trunk port and configure sub-interface for each of the VLANS and firewall the traffic between them.

https://supportforums.cisco.com/community/netpro/expert-corner#view=webcasts

Upcoming Live Webcast in English: January 15, 2013
Troubleshooting ASA and Firewall Service Modules

Register today for this Cisco Support Community live webcast.

-Kureli

Thanks Kureli,

I will attend the webcast, but from my understanding for the above solution the default gateway for all the vlans has to be moved from the core switches to the ASA ?

jpeterson6
Level 2
Level 2

Unfortunately, if you want the ASA to do all the filtering, you will need to move your VLAN Gateways to the ASA.

If the SVIs stayed on the switch then the traffic will never be sent to the ASA .

-Kureli

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card