Virtual Switch / Port Group

someone
someone Posts: 6  Freshman Member

Hello, I am new to Zyxel Switches, but I cannot find an option to create virtual Switches (as in VMWare VSphere Port Groups) that keep groups of ports completely separated from each other (independent of VLAN).
I think it would be much clearer to the user which groups/sets of ports can NOT communicate with each other, if they could be assigned to port groups in such a way that clearly separates them from each other in the GUI and "physically" (using separate ARP and routing tables, etc.). Otherwise there is a chance of misconfiguration, when configuring a subset of physical ports for a specific, isolated use case from the rest, even when leaving the default VLAN active for all ports.

Sometimes would be is useful to have a set of ports completely isolated from the rest (e.g. for connecting IPMI / Management ports). Adding a separate physical Switch would be rather wasteful in terms of cost, rackspace and energy use.

Achieving this using VLANs seems more Error-prone (misconfiguration, leftover or temporary VLAN assignments from bypassing such a restriction, etc) and not very simple / user-friendly to set up (at least without a Port-centric VLAN config screen)

In addition there is the security risk of spoofing - especially when also making use dynamic features such as VLAN assignment by Protocol / MAC / VendorID / Subnet for the regular ports

0 votes

Active · Last Updated

Comments

  • Zyxel_Judy
    Zyxel_Judy Posts: 1,934  Zyxel Employee
    Zyxel Certified Network Engineer Level 2 - Nebula Zyxel Certified Network Engineer Level 2 - Switch Zyxel Certified Network Engineer Level 2 - Security Zyxel Certified Network Engineer Level 1 - Nebula

    Hi @someone ,

    Based on your description, we believe physical switches can support these functionalities.
    Could you please share on the specific scenario and application where you want to use a virtual switch within a physical switch?
    Also, could you share which switch vendor and model supports virtual switching? This information will help us research and provide better feedback.

  • PeterUK
    PeterUK Posts: 3,645  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary
    edited February 26

    It sounds like port based VLAN is what you want which is on some of Zyxel switches when enabled from 802.1Q to Port Based

    Been some time when I last looked at it I think the above does.
    Port 1,9 and 10 are on there own
    Port 2,3,4 are in a group with port 8 as uplink
    Port 5,6,7 are in a group with port 8 as uplink