Well than your best (most secure way) is to use a VACL with vlan maps and permit traffic both ways like matt is saying. If you look at my first post you can see how to do this. Dont worry, Reading to much gets the best of all of us :). Never be afrai...
to clear things up a little. The purpose of a VACL is so you can permit or deny traffic INSIDE your VLAN itself (machine in the same layer 2 domain). When you said "deny vlan 3 and permit dns etc...I took this as something you wanted. If you are just...
Yeah that looks pretty solid..So the end result would be any routes being redistributed FROM BGP into OSPF will not be redistributed BACK into BGP to its neighbors.I would check this route-map out real quick:route-map myroutes permit 10 match ip addr...