10-08-2018 01:28 AM - edited 03-05-2019 10:58 AM
Hello everybody,
I have 1000V (or similar) router which has legs using subinterfaces in 10 or more VLANs. The intended deployment is LISP mobility by stretching subnets to multiple locations and IPSEC/SSL VPN accessing these VLANs from Internet.
However, there is a requirement that this router should not allow communication between subinterfaces do to the fact that each project/network/VLAN is separate project belonging/operated by different customers.
Is there a way to accomplish this without using firewall or access lists? Also, the router is not the default gateway for these networks/VLANs.
Thanks
10-08-2018 02:27 AM - edited 10-08-2018 02:30 AM
Hello
@irakli_n wrote:
Hello everybody,
I have 1000V (or similar) router which has legs using subinterfaces in 10 or more VLANs. The intended deployment is LISP mobility by stretching subnets to multiple locations and IPSEC/SSL VPN accessing these VLANs from Internet.
However, there is a requirement that this router should not allow communication between subinterfaces do to the fact that each project/network/VLAN is separate project belonging/operated by different customers.
Is there a way to accomplish this without using firewall or access lists? Also, the router is not the default gateway for these networks/VLANs.
Thanks
Yes using vrf lite have a look at example I shared in a previous post: - here
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide