We just recently purchased a Cisco 2948G-l3 layer 3 switch, in hopes to replace our Windows Router. In the process of installing the Router/Switch we found that our separation of networks on the FastEthernet ports was quite a task. We were not able to find a solution. Here is what we are facing.
We have 4 network subnets.
x.x.1.x is our private wired network on VLan 1
x.x.3.x is our private wireless network on VLan 2
x.x.4.x is our public wireless network on VLan 2
x.x.5.x is our private non-dhcp wired network on VLan 5
So far on out 2948G-L3 we have port configurations as follows:
Port 1 - x.x.2.2 (connected to our firewall x.x.2.1)
Port 2 - x.x.1.3 (our private wired gateway)
Port 3 - x.x.3.1 (our private wireless gateway)
Port 4 - x.x.4.1 (our public wireless gateway)
Port 5 - x.x.5.1 (our private non-dhcp wired gateway)
Port 1 should accept traffic from all networks.
Port 2 should block traffic from 4.x and 5.x and accept 1.x, 2.x, and 3.x.
Port 3 should block traffic from 4.x and 5.x and accept 1.x, 2.x, and 3.x.
Port 4 should block 1.x, 3.x, and 5.x and accept 2.x and 4.x.
Port 5 should block 1.x, 3.x, and 4.x and accept 2.x and 5.x.
Not too complicated, but from what I've found out I cannot use ACL's to filter traffic, that is I can't use them on the FastEthernet Ports, only gigabit. I've tried some limited VLan settings, but have found nothing to work too well. Is there anything that I should be taking a look at to do this or should I find some alternate form of filtering?
We have 4 network subnets.
x.x.1.x is our private wired network on VLan 1
x.x.3.x is our private wireless network on VLan 2
x.x.4.x is our public wireless network on VLan 2
x.x.5.x is our private non-dhcp wired network on VLan 5
So far on out 2948G-L3 we have port configurations as follows:
Port 1 - x.x.2.2 (connected to our firewall x.x.2.1)
Port 2 - x.x.1.3 (our private wired gateway)
Port 3 - x.x.3.1 (our private wireless gateway)
Port 4 - x.x.4.1 (our public wireless gateway)
Port 5 - x.x.5.1 (our private non-dhcp wired gateway)
Port 1 should accept traffic from all networks.
Port 2 should block traffic from 4.x and 5.x and accept 1.x, 2.x, and 3.x.
Port 3 should block traffic from 4.x and 5.x and accept 1.x, 2.x, and 3.x.
Port 4 should block 1.x, 3.x, and 5.x and accept 2.x and 4.x.
Port 5 should block 1.x, 3.x, and 4.x and accept 2.x and 5.x.
Not too complicated, but from what I've found out I cannot use ACL's to filter traffic, that is I can't use them on the FastEthernet Ports, only gigabit. I've tried some limited VLan settings, but have found nothing to work too well. Is there anything that I should be taking a look at to do this or should I find some alternate form of filtering?