I have three vlans on a 3750: 50, 51, and 52. I currently have ip routing enabled and all traffic is routing between the three vlans okay, but now I want to limit traffic to vlan 50 (use 50 as the management vlan and 51 and 52 for access vlans). do i just do this with an access-list that denies traffic from one vlan's subnet to another, or is there a way to specify ACLs directly so the filtering is at layer 2? can someone give me an example or some reference documentation?
thanks.
matt