Chapter 5 Tutorials

5.6How to Use Private VLAN to Do Port Isolation in aVLAN

This tutorial is not applicable to the XGS1910-24 or XGS1910-48.

Port isolation prevents communication between ports. You want to do port isolation in a VLAN but still allow ports to access the Internet or network resources through the uplink port in the same VLAN. You use private VLAN to do port isolation in a VLAN instead of assigning each port to a separate VLAN and creating a different IP routing domain for each individual port.

By default, all ports on the Switch are in VLAN 1 and private VLAN 1. An isolated port is a port on which port isolation is enabled. An isolated port cannot communicate with other isolated ports even when they are in the same VLAN and same private VLAN.

Internet

In this example, you put ports 2 to 4 and 25 in private VLAN 25 and enable port isolation to block traffic between ports 2, 3 and 4.

5.6.1 Creating a Private VLAN

Follow the steps below to configure port 2, 3, 4 and 25 as a member of private VLAN 25.

1Access the web configurator through the Switch’s port on which port isolation will not be enabled.

2Go to Configuration > Private VLANs > PVLAN Membership. Click Add New Private VLAN.

3Enter a private VLAN ID (25 for example) in the PVLAN ID field.

4Select ports 2, 3, 4 and 25 to be members of this private VLAN.

44

 

GS1910/XGS1910 Series User’s Guide