VLAN-specific protected ports (GS1900-24HPv2)

Options
nemSoma
nemSoma Posts: 1
edited August 2022 in Switch
Hey all,

I have a GS1900-24HPv2 switch.
I have two wireless access points connected to port 1 & port 2 of my switch.
Both access points are hosting a main and a guest Wi-Fi network, which are on VLANs 1 and 2 respectively. (PVID is 1 for port 1 & 2, while VLAN 2 is tagged)
I want to set it up so that clients of the guest Wi-Fi can't talk to each other, but the clients of the main Wi-Fi can.
My switch has a "Protected Port" feature, which if I enable on two ports of my switch, it will block communication between those two ports.
My problem is that if I enable this feature on port 1 & 2, it will block communication not only between the clients of the guest network, but the main network as well (assuming the two clients are connected to different access points).

Is there a way to do what I want on this switch?

All Replies

  • Zyxel_Chris
    Zyxel_Chris Posts: 661  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer
    Options
    Welcome to Zyxel community!! @nemSoma :)
    There are another ways which is more fits in this case, if you use NSG/USG Flex as the gateway then can activate the guest Vlan in interface setting page.
     
    If you don't have Nebula gateway then can configure in AP SSID settings (your guest VLAN ssid), please note that you need to put gateway MAC address, also the DHCP server MAC if you have another server for it.


    Chris
  • Zyxel_Chris
    Zyxel_Chris Posts: 661  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer
    Options
    @nemSoma
    If your switch is standalone then "VLAN isolation" can fulfill this case but GS1900 does not support this feature please use GS1920 or GS2220 series instead.  
    Chris