I wish to add 2 VLANs to an existing Layer 3 switch. I am currently testing using another switch with the same config.
I want them to be able to talk to eachother, but not to the main VLAN (VLAN1). I've added ACLs In/Out (to allow dest/source of new VLAN IP ranges) on the new VLAN interfaces (not touched Vlan1) and everything is working as I wish, expect that hosts on VLAN1 can still ping the layer 3 interfaces for the new VLANs that live on the switch..despite the only permit rules being for IPs in the new subnets. They cannot get any further, though. I don't really want the new addresses pingable from production machines, and I would rather not add ACLs to VLAN1.
Any ideas where I am going wrong? Sorry if this is a little vague!
I want them to be able to talk to eachother, but not to the main VLAN (VLAN1). I've added ACLs In/Out (to allow dest/source of new VLAN IP ranges) on the new VLAN interfaces (not touched Vlan1) and everything is working as I wish, expect that hosts on VLAN1 can still ping the layer 3 interfaces for the new VLANs that live on the switch..despite the only permit rules being for IPs in the new subnets. They cannot get any further, though. I don't really want the new addresses pingable from production machines, and I would rather not add ACLs to VLAN1.
Any ideas where I am going wrong? Sorry if this is a little vague!
Last edited: