Hello everybody,
I have 1000V (or similar) router which has legs using subinterfaces in 10 or more VLANs. The intended deployment is LISP mobility by stretching subnets to multiple locations and IPSEC/SSL VPN accessing these VLANs from Internet.
However, there is a requirement that this router should not allow communication between subinterfaces do to the fact that each project/network/VLAN is separate project belonging/operated by different customers.
Is there a way to accomplish this without using firewall or access lists? Also, the router is not the default gateway for these networks/VLANs.
Thanks