08-25-2016 05:49 AM - edited 03-08-2019 07:08 AM
I created a local network with several computers and I want to allow computers
192.168.0.3
192.168.0.4
Talk only with computer 192.168.0.1
* During the bereaved computer received its own VLAN
(192.168.0.3 192.168.0.4 computers in a shared VLAN)
how do I do it?
08-25-2016 06:49 AM
Hi due to them being in the same subnet/vlan same broadcast domain the pcs will communicate through arp so if you wanted them not to speak to each other you would need to block them at layer 2 instead of layer 3 through an ip access list on the vlan
the way to do that is either a vacl or mac acl but not all software and platforms support this
another way to do it is setup private vlans as you can allow all the ports in same community and isolate the others
these are some options but you may not have them in PT
http://www.cisco.com/c/en/us/td/docs/switches/datacenter/nexus5000/sw/configuration/guide/cli/CLIConfigurationGuide/PrivateVLANs.html
http://www.cisco.com/c/en/us/td/docs/switches/datacenter/nexus1000/sw/4_0/security/configuration/guide/n1000v_security/security_9mac_acls.html
http://www.cisco.com/c/en/us/tech/lan-switching/vlan-access-lists-vacls/index.html
08-25-2016 04:43 PM
This looks like a school project.
Wrong forum.
Kindly post this line of questioning at the Cisco Learning Network.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide