Tomorrow morning I need to set up routing between two VLANs on a 2950. Both VLANs need access to outside but traffic is not allowed to flow between them. The router is a 3745.
This will be my first time doing this so I'd appreciate it if someone would check my configs and verify that I'm not missing anything.
Here's my config for the switch: int f0/1 switchport mode trunk switchport access vlan 1 switchport trunk native vlan 1
Here's my config for the router: int f0/0 no ip address int f0/0.1 encapsulation dot1q 1 ip address 192.168.195.25 255.255.255.252 int f0/0.2 encapsulation dot1q 2 ip address 172.16.98.1 255.255.255.0
Here's how I propose to prevent access from one VLAN to the other. Will this work? Does the access-group get applied to the major interface or the subinterface?
ip access-list extended no_route deny ip 192.168.195.0 0.0.0.255 172.16.98.0 0.0.0.255 deny ip 172.16.98.0 0.0.0.255 192.168.195.0 0.0.0.255 permit ip any any
int f0/0 ip access-group no_route in