Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
I think you can create an inbound access-list and apply it to the vlan.access-list 101 deny ip host anyaccess-list 101 permit ip any anyI am assumming that you are using the switch as an L3 switch
Can you please specify the switches that you are using on the LAN. If you are using 3750, then the below link can help.http://www.cisco.com/en/US/products/hw/switches/ps5023/products_tech_note09186a0080883f9e.shtml