cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
306
Views
0
Helpful
1
Replies

Isolated Private Vlan for unsuported switch

syves
Level 1
Level 1

Dear All

I have a DMZ subnet outside my firewall which have all my client router connected to it. I do not have control of these routers. I require to stop these routers to be able to talk to each others. I saw the Isolated Private VlANs feature on some catalyst Switches which would be ideal but my switch do not support the feature. How can I achieve the same function, I need to restrict port A and B which have my customer router connected to talk to each other but let both port talk to port C which is my firewall port. All these hosts are part of the same subnet /24.

Regards Yves

1 Reply 1

irelandsky
Level 1
Level 1

I think you can use the layer 2 ACL based on MAC address instead of IP address.

Marco