Port Isolation
Posted: Thu Nov 06, 2014 11:00 pm
Hello,
I've been told twice that the WS supports some form of port isolation. It clearly does not, at least from what I can tell.
Lets say for example, I have port 1 connected to my router, running both tagged and untagged vlans.
Lets say I have three AP's connected to ports 2, 3 & 4 on the WS, trunked back to my router, using vlans, 9, 8 & 7. (every AP in it's own network) fine.
Now lets say I have VLAN's my customer traffic rides in. The CPE is immaterial, just assume it's tagging a VLAN up to the AP to get it's public IP. (see attached image)
The problem I have is the three customer vlans are now in what is basically a four port switch between port 1-4. So IF a customer on port 4 had their CPE in bridge mode and plugged in to their routers LAN port, a customer on port 2 requesting dhcp might get an address from the customer on port 4.
I want to be able to tell the tagged vlans on ports 2,3 &4 they can only talk to port 1 and not to each other.
I do this now using spit horizon bridging on mikrotik and it works awesome.
All this said.... I'm getting to be less worried about this feature since all new customer CPE's go in to router mode instead of bridge mode. Additionally, with this setup at least it would be isolated to the one tower/switch because my VPLS tunnels from the tower router to the core will still have SPB running.. But I think for WISP this would be an awesome feature and will prove to be very useful. I'm not sure it's going to be easy to add and keep "simple" theme or not though. I'd be happy if I could enable it from the CLI even.
Thanks for taking the time to read this lengthy post. I'm very hopeful and excited about these switches.
I've been told twice that the WS supports some form of port isolation. It clearly does not, at least from what I can tell.
Lets say for example, I have port 1 connected to my router, running both tagged and untagged vlans.
Lets say I have three AP's connected to ports 2, 3 & 4 on the WS, trunked back to my router, using vlans, 9, 8 & 7. (every AP in it's own network) fine.
Now lets say I have VLAN's my customer traffic rides in. The CPE is immaterial, just assume it's tagging a VLAN up to the AP to get it's public IP. (see attached image)
The problem I have is the three customer vlans are now in what is basically a four port switch between port 1-4. So IF a customer on port 4 had their CPE in bridge mode and plugged in to their routers LAN port, a customer on port 2 requesting dhcp might get an address from the customer on port 4.
I want to be able to tell the tagged vlans on ports 2,3 &4 they can only talk to port 1 and not to each other.
I do this now using spit horizon bridging on mikrotik and it works awesome.
All this said.... I'm getting to be less worried about this feature since all new customer CPE's go in to router mode instead of bridge mode. Additionally, with this setup at least it would be isolated to the one tower/switch because my VPLS tunnels from the tower router to the core will still have SPB running.. But I think for WISP this would be an awesome feature and will prove to be very useful. I'm not sure it's going to be easy to add and keep "simple" theme or not though. I'd be happy if I could enable it from the CLI even.
Thanks for taking the time to read this lengthy post. I'm very hopeful and excited about these switches.