Ok This is my setup
Vlan1-192.168.1.0/24
vlan2-192.168.2.0/24
vlan3-192.168.3.0/24
I have tested the vlan settings and all works correctly. My Issue is when I need to seperate all three vlans so that they can not talk to each other but still can get to the internet.
right now when I attempt to ping from 192.168.1.2 to 192.168.3.2 I get a reply. How can I block all traffic between the three networks.
Or with just one assuming that all three VLANs are supposed to reach some other interface you can do this statefully and go for a default drop policy, which is a good idea anyway. Let’s assume that interface connects to the Internet and is called WAN: