options to segregate host on a LAN
We have a /24 LAN configured on a vlan interface. It has been requested to segregate one host on the LAN so it can only reach other LAN hosts via defined policies.
Is it possible to do this without changing the host IP address, subnet and default gateway?
For instance, is there any way that can two VLANs be treated as one interface in terms of their subnet but control traffic between them using policies?
We have a lot of flexibility with VLAN configuration. We do not currently use zones but I do not believe this would help.
The managed switches support private VLAN, but this is not an option since we have multiple switches on the LAN (the privacy setting is restricted to the local switch only).
From what I can see this is not possible, but it is certainly worth asking.
If there are no other options we'll just assign a new IP range to the host and proceed with a regular layer 3 solution. But it would be very nice to do this somehow "in the background". And it would be very useful elsewhere - Oh, all those stray devices I could isolate!
