Why can't all users access the management interface on the router unless blocked by ACL? I can be on any of my different networks and access my router interface including VLAN1 the default VLAN.
Your diagram doesn't show VLAN1 on the router. I only see VLAN99 and VLAN102. Using a trunk port can transfer routing from the layer 3 switch to the router.
PS
I guess I can add all my network equipment has an IP address in VLAN1 except my internet router. I don't want the internet router looking at any traffic except internet traffic. If I add VLAN1 traffic to my internet router then it will be slowed down by chatty talk from devices to windows chatty talk and everything else on the LAN including broadcast traffic as the router needs to look at all packets crossing it's interface. I want my internet router talking to the internet parallel as all this broadcast traffic is trapped in a different VLAN. This is where you gain through put with an isolated router as the internet router is not waiting on local LAN traffic in different VLANs.
Your diagram doesn't show VLAN1 on the router. I only see VLAN99 and VLAN102. Using a trunk port can transfer routing from the layer 3 switch to the router.
PS
I guess I can add all my network equipment has an IP address in VLAN1 except my internet router. I don't want the internet router looking at any traffic except internet traffic. If I add VLAN1 traffic to my internet router then it will be slowed down by chatty talk from devices to windows chatty talk and everything else on the LAN including broadcast traffic as the router needs to look at all packets crossing it's interface. I want my internet router talking to the internet parallel as all this broadcast traffic is trapped in a different VLAN. This is where you gain through put with an isolated router as the internet router is not waiting on local LAN traffic in different VLANs.
Last edited: