Wednesday, September 1, 2021

Isolating a VLAN Help (Aruba)

I need a VLAN whose purpose is solely to connect two devices between two switches without being able to see any other VLAN (and vice versa). Unfortunately, even without assigning an IP on that VLAN to allow inter-VLAN routing, it can still manage to see IPs on other VLANs.

Aruba 3810M <--> Aruba 2390

  • Interface VLAN 20 created on both switches.
  • ip routing is enabled on the 3810M, however no IP address has been assigned to the VLAN (on either switch).
  • A single interface on both switches configured for that VLAN (untagged 1/10) and the trunk port going between the two switches configured for that VLAN (tagged trunk1).

On a Cisco / Arista, I'd just throw these ports in their own VRF -- but (unless I'm missing something, which is possible) it does not appear that an Aruba 3810M can do VRFs. (I found it in ArubaOS-CX, but not ArubaOS-Switch.)

Any ideas on how I can isolate this thing? Much appreciated!



No comments:

Post a Comment