Question : vlan isolation - need to keep a vlan from seeing network

I have mutlple VLans on HP switches. All  is running great.  I want to bring up Guest Vlan and isolate them from seeing the rest of the network, and just route them out to the internet.   Currently we have all our Vlans going to our core (hp 5412zl) which does all the routing.  From the Core if need be traffic goes out to the internet.   I want to set it so all the traffinc on the guest Vlan.. ONLY goes out to the internet.     The guest Vlan runs fine and can go out to the internet, BUT it also sees the rest of the network.

Thanks

Answer : vlan isolation - need to keep a vlan from seeing network

A basic solution would be to use an access-list to block all traffic FROM the guest subnet TO the Internal subnets.

You could also use a routing policy such that traffic FROM guest going to Internal is sent to the black hole.

Another solution would be install a Firewall in between - Ideal solution

Terminate guest vlan gateway on a seperate Internet router/link

Finally, i suppose you could also use private vlans to accomplish this.



Random Solutions  
 
programming4us programming4us