hey thanks for the reply
>First cut; I agree with your consultant. If you want to block vlan access, it has to be done on the L3 closest to the vlans.
i was hoping to tackle the vlan issue later, although all the switches have already been configured with vlans ( i just added it to them ). do u mean that this has to be solved via vlan ? forgive me im a real newbie...
>However, I need a little help with components. Who makes a 4950 ? Which 3Com firewall? Does the Linux box act as the internet router? sm and xm switches? I am assuming you have a small group of hosts that need internet access without access to proprietary systems.
3com 4950 switch, for now the linux box acts as a temporary internet router ( consultant says if possible not to focus the routing on the linux box.... he says the 4950 is the "key" ).... 3com SUper Stack III 3300 XM and SM switches.. yup we have a couple of hundred hosts ( on different subents ).. needing access to the net and to mail servers ( not yet a problem.. coz it hasnt been transferred to the old network

..) yes you are right.. they shouldnt be able to access the switches.. firewall.. router <-- ( gateway(?!) )...
>The basic ways to do this:
Create a separate network/vlan. Connect it to the DMZ of the firewall on the outside of your network. Several variations.
Use policy routing on the Layer 3 device to send traffic to the firewall. Let the firewall rules determine access.
Use filters on the L3 device. Example, if source address is 192.x.x.x and destination 10.y.y.y, next hop nul0:
hmmm... honestly i cant fully understant this... in the 4950 switch there are options for which networks are allowed access ... or denial... hmmm, ill be back this monday ( gmt +8) to try to find the settings for this.. ive been looking at the options.. but im not sure ive found filters in there... with the routing option you can place, the network address ( destination ), the subnet mask and the gateway... and a vlan id that's all... for now i removed the firewall to simplify things... also, i do not know a next hop nul0....
im learning stuff everyday.. unfortunately.. it is insufficient..! help! pls?
ive been reading pdfs from 3com/cisco.. but apparently layer 3 switching for the 4950 is only an upgrade and therefore lacks the necesary instructions to make it work...
>If you want to e-mail me a diagram, feel free.
done, i hope it can help you help me!
thanks!