03-25-2015 02:52 AM - edited 03-07-2019 11:15 PM
Hi Guys,
Question..
I have a switch with private vlans enabled.
I want to be able to manage the switch remotely, So id like to create a L3 vlan like normal. However, how can I have this vlan in a isolated vlan like a physical interface would be?
I dont want the switch to be able to communicate with anything else on the isolated network via its L3 interface.
Any thoughts?
Thanks
L
03-25-2015 03:06 AM
Hi Graham,
The most secure thing to do is write an access-list and allow SSH for remote access via the I.P of your PC only.
Regards.
03-26-2015 01:48 AM
Thanks, but this really isnt an ideal method here.
Is there really no way to have a leyer3 interface in an isolated vlan? ( just like a port would be? )
Thanks
03-26-2015 08:18 AM
Graham
It's not entirely clear what you mean.
If you want the SVI to be entirely separate on the switch then you should be able to use a VRF depending on your switch model and feature set.
If you put the SVI into the VRF you cannot route to that SVI from any other SVIs on the switch or any other IP subnets on your network.
Which means the route for that vlan/IP subnet won't be in the routing tables of any of your other L3 devices so it depends on what you mean by managing it remotely.
Jon
10-04-2015 11:42 AM
You can find some ideas in this article of mine:
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide