cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
239
Views
0
Helpful
2
Replies

Isolating a LAN

bevans
Level 1
Level 1

We have a network that is VLANed out per building. I have a group of computers that is going to be running TCP/IP and NetBEUI. I would like to isolate these computers on their own VLAN, so as to control broadcasts and such. Would it be necessary to go further with this, ie creating access lists?

Bill E.

2 Replies 2

Bobby Thekkekandam
Cisco Employee
Cisco Employee

If NetBEUI Broadcasts are the main concern, then simply putting the hosts in their own VLAN is sufficient.

NetBEUI is nonroutable, so the broadcasts will be contained within the VLAN/subnet.

tbaranski
Level 4
Level 4

Whether or not you need to go further than VLANs depends on what the security requirements are. If the requirement is that the two VLANs can't talk to each other at all or can only do so in a limited fashion, then you'll need access lists to filter traffic between them. The only traffic VLANs in of themselves will stop are broadcasts/multicasts, or unroutable protocols (as mentioned).