I want to segment a 3750 so wireless APs are on a separate VLAN from all other traffic. Lets say that wireless ports are on VLAN 20 and the rest are on VLAN 10. VLAN 20 traffic is only allowed to get to a particular printer on VLAN 10 and out to the Internet. I think of this as trying to filter packets as traffic is about to leave VLAN 20 and enter VLAN 10. Where do I apply the access-group statement and in which direction to accomplish what I want?
I do not manage the edge router so I cannot set up VLAN trunking between the router and the switch. Is there a way to untag all packets going out the switch port to the router?
I suppose CDP and VTP traffic is handled by setting the switchport trunk native vlan parameter for dot1q. Should this be set to the management vlan? How is this type of traffic handled with ISL encapsulation? Does it get assigned to VLAN 1 automatically?