ZyXEL GS1910-24 User Guide - Page 44

How to Use Private VLAN to Do Port Isolation in a VLAN, 5.6.1 Creating a Private VLAN, Internet

Page 44 highlights

Chapter 5 Tutorials 5.6 How to Use Private VLAN to Do Port Isolation in a VLAN This tutorial is not applicable to the XGS1910-24 or XGS1910-48. Port isolation prevents communication between ports. You want to do port isolation in a VLAN but still allow ports to access the Internet or network resources through the uplink port in the same VLAN. You use private VLAN to do port isolation in a VLAN instead of assigning each port to a separate VLAN and creating a different IP routing domain for each individual port. By default, all ports on the Switch are in VLAN 1 and private VLAN 1. An isolated port is a port on which port isolation is enabled. An isolated port cannot communicate with other isolated ports even when they are in the same VLAN and same private VLAN. Internet In this example, you put ports 2 to 4 and 25 in private VLAN 25 and enable port isolation to block traffic between ports 2, 3 and 4. 5.6.1 Creating a Private VLAN Follow the steps below to configure port 2, 3, 4 and 25 as a member of private VLAN 25. 1 Access the web configurator through the Switch's port on which port isolation will not be enabled. 2 Go to Configuration > Private VLANs > PVLAN Membership. Click Add New Private VLAN. 3 Enter a private VLAN ID (25 for example) in the PVLAN ID field. 4 Select ports 2, 3, 4 and 25 to be members of this private VLAN. 44 GS1910/XGS1910 Series User's Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76

Chapter 5 Tutorials
GS1910/XGS1910 Series User’s Guide
44
5.6
How to Use Private VLAN to Do Port Isolation in a
VLAN
This tutorial is not applicable to the XGS1910-24 or XGS1910-48.
Port isolation prevents communication between ports. You want to do port isolation in a VLAN but
still allow ports to access the Internet or network resources through the uplink port in the same
VLAN. You use private VLAN to do port isolation in a VLAN instead of assigning each port to a
separate VLAN and creating a different IP routing domain for each individual port.
By default, all ports on the Switch are in VLAN 1 and private VLAN 1. An isolated port is a port on
which port isolation is enabled. An isolated port cannot communicate with other isolated ports even
when they are in the same VLAN and same private VLAN.
In this example, you put ports 2 to 4 and 25 in private VLAN 25 and enable port isolation to block
traffic between ports 2, 3 and 4.
5.6.1
Creating a Private VLAN
Follow the steps below to configure port 2, 3, 4 and 25 as a member of private VLAN 25.
1
Access the web configurator through the Switch’s port on which port isolation will not be enabled.
2
Go to
Configuration > Private VLANs > PVLAN Membership
. Click
Add New Private VLAN
.
3
Enter a private VLAN ID (25 for example) in the
PVLAN ID
field.
4
Select ports 2, 3, 4 and 25 to be members of this private VLAN.
Internet