cancel
Showing results for 
Search instead for 
Did you mean: 

intra-vlan traffic block

intra-vlan traffic block

Giuseppe_Montan
Contributor

Good Morning, I am looking a way to block intravlan traffic.

I have a couple of 5520 as core and lot of X440G2 as access.

I have a Vlan that is configured over all switches.

It can communicate with Internet and other vlan  but the users on this vlan can not communicate eachother.

Probably privatevlan is the right way but i can not confgure on core switch ( cause the subscriver vlan has ip address configured )

Anyone know hot to solve ?

Thanks

Giuseppe

4 REPLIES 4

OscarK
Extreme Employee

Take a look at port isolation for the core switch, very simple. 

Ports with isolation set to on cannot communicate with eachother.

I used a dynamic ACL 😞 but I am not shure is the right way ( It works but I do not like it )

I tried also to block traffic between VLAN in only one way

source 192.168.199.0 to destination 192.168.188.0 DENY

source 192.168.188.0 to destination 192.168.199.0 PERMIT

If I create the first dynamic ACL I deny all traffic ( ingress and egress ) between this vlan and this is not I need.

Giuseppe

Giuseppe_Montan
Contributor

Thanks, can you give me an example ?

Giuseppe

gfriedl
Extreme Employee

i would build an IP ACL, that redirect all IP packets to the default Gateway IP of choice ... drop all other ip packets.

GTM-P2G8KFN