So, I have campus LAN, implemented as many VLANs with InterVLAN routing, that spreads on tens of L2 switches and one L3 switch. Now, I have request that hosts on one VLAN don't see each other. But, those hosts, on that VLAN, are spread on many different switches.
So, my questions are:
Do I have to configure/define all of the existing VLANs as Primary and Secondary types, or only the one I need to isolate?
What of the existing VLANs would be primary VLAN? Or should I create new VLAN and define it as Primary?
Trunk ports between the switches will be Promiscuous ports?