I have inherited a series of 2950 switches and a 2600 router. Multiple VLANs are configured and are trunked to the router. The router has been configured with multiple IP addresses using subinterfaces with 802.1q encapsulation.
For security purposes, I need to completely isolate traffic from one VLAN to another. As it stands now, a host on one VLAN can potentially access a host on any other as the router provides connectivity. I've tried using access lists to disable inter-VLAN traffic on the router but they ain't working. Do I need to get away from 802.1q encapsulation and use secondary addresses instead or does anyone have any other ideas? Thanks.
For security purposes, I need to completely isolate traffic from one VLAN to another. As it stands now, a host on one VLAN can potentially access a host on any other as the router provides connectivity. I've tried using access lists to disable inter-VLAN traffic on the router but they ain't working. Do I need to get away from 802.1q encapsulation and use secondary addresses instead or does anyone have any other ideas? Thanks.