Have a cisco 3750 as the core switch with multiple VLANs. One VLAN is a vlan for public access with a port connected directly to the DMZ of a firewall.
Since IP Routing is enabled on the 3750 to allow routing between VLANs, we need to stop this on this particular VLAN. The purpose is to extend the Public access to another building over the trunk links.
I've tried access-lists and looked into VACLS but cannot find what I need. Here's a synopsis of the config: VLAN 10 - 192.100.10.0/24 VLAN 11 - 192.100.11.0/24 VLAN 12 - 192.100.12.0/24
VLAN 19 - 172.16.1.0/24 - Public/DMZ
When I enable a port in VLAN 19 and connect to my DMZ (IP address of
172.16.1.1), then any PC on any VLAN can ping/access the DMZ. I need to stop this routing to this network via the internal router of the switch.Thanks for any input or direction.
Ron