cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
432
Views
0
Helpful
3
Replies

Allow traffic from a VLAN to communicate with only the router

josephnunham
Level 1
Level 1

Hello,

I'm sure this is a simple answer, but I can't seem to find one that sounds like a positive solution. I have two VLANs set up on a Catalyst 2950 switch: VLAN 1 (192.168.1.x) and VLAN 2 (192.168.2.x). VLAN 2 can ping the router on the 192.168.1.x network and nothing else, which is what I want. However, computers on the 192.168.1.x network can ping computers on VLAN 2, which is what I do not want. I want to make it where VLAN 1 and VLAN 2 cannot communicate with one another, but that VLAN 2 can still ping the router on VLAN 1. I've read about access control lists and ip tables, but which one is the definite solution?

Thank you for your guidance.

3 Replies 3

lgijssel
Level 9
Level 9

This must be achievable with access lists.

regards,

Leo

Hi Leo,

Could you tell me how they are possible in the 2950? I read some places that since it is a L2 device it does not support ACLs.

Thank you.

kishorecisco
Level 1
Level 1

Hi,

It should be possible using an ACL and also try to use distribute list.

regards,

kishore

Review Cisco Networking for a $25 gift card