VLAN-specific protected ports (GS1900-24HPv2)
Hey all,
I have a GS1900-24HPv2 switch.
I have two wireless access points connected to port 1 & port 2 of my switch.
Both access points are hosting a main and a guest Wi-Fi network, which are on VLANs 1 and 2 respectively. (PVID is 1 for port 1 & 2, while VLAN 2 is tagged)
I want to set it up so that clients of the guest Wi-Fi can't talk to each other, but the clients of the main Wi-Fi can.
My switch has a "Protected Port" feature, which if I enable on two ports of my switch, it will block communication between those two ports.
My problem is that if I enable this feature on port 1 & 2, it will block communication not only between the clients of the guest network, but the main network as well (assuming the two clients are connected to different access points).
Is there a way to do what I want on this switch?
I have a GS1900-24HPv2 switch.
I have two wireless access points connected to port 1 & port 2 of my switch.
Both access points are hosting a main and a guest Wi-Fi network, which are on VLANs 1 and 2 respectively. (PVID is 1 for port 1 & 2, while VLAN 2 is tagged)
I want to set it up so that clients of the guest Wi-Fi can't talk to each other, but the clients of the main Wi-Fi can.
My switch has a "Protected Port" feature, which if I enable on two ports of my switch, it will block communication between those two ports.
My problem is that if I enable this feature on port 1 & 2, it will block communication not only between the clients of the guest network, but the main network as well (assuming the two clients are connected to different access points).
Is there a way to do what I want on this switch?
0
All Replies
-
Welcome to Zyxel community!! @nemSoma
There are another ways which is more fits in this case, if you use NSG/USG Flex as the gateway then can activate the guest Vlan in interface setting page.
If you don't have Nebula gateway then can configure in AP SSID settings (your guest VLAN ssid), please note that you need to put gateway MAC address, also the DHCP server MAC if you have another server for it.
0 -
@nemSoma
If your switch is standalone then "VLAN isolation" can fulfill this case but GS1900 does not support this feature please use GS1920 or GS2220 series instead.0
Categories
- All Categories
- 415 Beta Program
- 2.5K Nebula
- 152 Nebula Ideas
- 101 Nebula Status and Incidents
- 5.8K Security
- 296 USG FLEX H Series
- 281 Security Ideas
- 1.5K Switch
- 77 Switch Ideas
- 1.1K Wireless
- 42 Wireless Ideas
- 6.5K Consumer Product
- 254 Service & License
- 396 News and Release
- 85 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.6K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 87 About Community
- 76 Security Highlight