Hi all,
I have four 3560G's on my LAN which run our production environment/domain from the default VLAN 1. The ports between the switches which connect each switch to another are trunked. What I'm trying to accomplish here is create another VLAN which is totally separate from the main VLAN 1 so each cannot talk to one another. The default VLAN (or VLAN 1) is 192.168.252.x. The VLAN 2 subnet will be 192.168.250.x.
The 192.168.252.1 gateway you see in the configs is our ISA server which is connected to the outside world. The ISA server is connected to a port on SWITCH-B. Only VLAN 1 should be able to hit the ISA server and Internet.
Here's the layout...
Switch-A:
- Port 49 trunked to port 49 on Switch-C
- VLAN 1 192.168.252.51
- VLAN 2
Switch-B:
- Port 49 trunked to port 50 on Switch-C
- VLAN 1 192.168.252.52
- VLAN 2
Switch-C:
- Port 49 trunked to port 49 on Switch-A
- Port 50 trunked to port 49 on Switch-B
- Port 51 trunked to port 49 on Switch-D
- VLAN 1 192.168.252.53
- VLAN 2 192.168.250.53
Switch-D:
- Port 49 trunked to port 51 on Switch-C
- VLAN 1 192.168.252.54
- VLAN 2
Is it possible to have a client on Switch-A talk to a client on Switch-D from VLAN 2 without clients from VLAN 1 and VLAN 2 being able to talk each other? Basically, I would like for the 252 subnet (VLAN 1) to be on one domain and the 250 (VLAN 2) be on another domain and not see each other.
I've attached a URL to the config's for each switch for review.
Thank you for helping me with my issues.
I have four 3560G's on my LAN which run our production environment/domain from the default VLAN 1. The ports between the switches which connect each switch to another are trunked. What I'm trying to accomplish here is create another VLAN which is totally separate from the main VLAN 1 so each cannot talk to one another. The default VLAN (or VLAN 1) is 192.168.252.x. The VLAN 2 subnet will be 192.168.250.x.
The 192.168.252.1 gateway you see in the configs is our ISA server which is connected to the outside world. The ISA server is connected to a port on SWITCH-B. Only VLAN 1 should be able to hit the ISA server and Internet.
Here's the layout...
Switch-A:
- Port 49 trunked to port 49 on Switch-C
- VLAN 1 192.168.252.51
- VLAN 2
Switch-B:
- Port 49 trunked to port 50 on Switch-C
- VLAN 1 192.168.252.52
- VLAN 2
Switch-C:
- Port 49 trunked to port 49 on Switch-A
- Port 50 trunked to port 49 on Switch-B
- Port 51 trunked to port 49 on Switch-D
- VLAN 1 192.168.252.53
- VLAN 2 192.168.250.53
Switch-D:
- Port 49 trunked to port 51 on Switch-C
- VLAN 1 192.168.252.54
- VLAN 2
Is it possible to have a client on Switch-A talk to a client on Switch-D from VLAN 2 without clients from VLAN 1 and VLAN 2 being able to talk each other? Basically, I would like for the 252 subnet (VLAN 1) to be on one domain and the 250 (VLAN 2) be on another domain and not see each other.
I've attached a URL to the config's for each switch for review.
Thank you for helping me with my issues.