First, let me start with what I'm trying to accomplish. The client has multiple servers, Server A, B, C, etc in the corporate site. They have multiple users, User A, B, C, etc. They want to allow User A to access Server A & B, but not C. User B to access Server B and C, but not A. They also have remote users connected via site-to-site VPN. Remote User A should only be able to access Server B, and so on and so forth.
So I'm thinking, the best way to handle this would be to setup a VLAN on the corporate site. What is the least expensive Cisco switch that will allow the above scenario. I've looked at the Cisco 2960 switches, but I'm unsure via the user documentation whether this is possible. As much as possible, the customer would not want to use an external router to route packets between VLANs. Ideally, overlapping VLANs should be supported by the switch or perhaps have built-in routing on the switch itself to accomplish the above requirements.
So I'm thinking, the best way to handle this would be to setup a VLAN on the corporate site. What is the least expensive Cisco switch that will allow the above scenario. I've looked at the Cisco 2960 switches, but I'm unsure via the user documentation whether this is possible. As much as possible, the customer would not want to use an external router to route packets between VLANs. Ideally, overlapping VLANs should be supported by the switch or perhaps have built-in routing on the switch itself to accomplish the above requirements.