cancel
Showing results for 
Search instead for 
Did you mean: 

Policy to deny traffc between vlan

Policy to deny traffc between vlan

Giuseppe_Montan
Contributor

Good Morning, a customer ask if is posible to create a policy ( on XMC ) to permit or deny the communication betwwen VLAN.

I am finding the old documentation about ACL or Policy on XOS, do you have something to help me ?

Thanks

Giuseppe

1 ACCEPTED SOLUTION

Tomasz
Valued Contributor II

Hi Giuseppe,

 

I’d consider to isolate inter-VLAN traffic on a routing device, using Policy rather to deny all and access specific protocols and hosts for the roles. That way the router takes care of inter-VLAN and Policy is about surgically precise access to protocols even within a VLAN, even on the same switch.

I shared some food for thoughts regarding this inter-VLAN communication issue here:

 

Hope that helps,

Tomasz

View solution in original post

1 REPLY 1

Tomasz
Valued Contributor II

Hi Giuseppe,

 

I’d consider to isolate inter-VLAN traffic on a routing device, using Policy rather to deny all and access specific protocols and hosts for the roles. That way the router takes care of inter-VLAN and Policy is about surgically precise access to protocols even within a VLAN, even on the same switch.

I shared some food for thoughts regarding this inter-VLAN communication issue here:

 

Hope that helps,

Tomasz

GTM-P2G8KFN