We are using Intervlan routing and no routing protocols. All departments sit on their own VLAN. Our core router is a WS-C4500x-32 that handles all routing for our environment. I am having huge trouble successfully constructing an VACL to allow hosts to get out to the internet but not communicate with each other.. Is this even possible without using private vlans?? If so, please help me understand what i am doing wrong.. The VACL either blocks all traffic or none.
ip access-list extended NO-VLAN2 10
permit ip 192.168.2.0 0.0.0.255 192.168.2.0 0.0.0.255
vlan access-map NO-VLAN2 10
action drop
match ip address NO-VLAN2
vlan access-map NO-VLAN2 20
action forward
vlan filter NO-VLAN2 vlan-list 2