![background image](http://html.mh-extra.com/html/zyxel-communications/mgs3520-series/mgs3520-series_user-manual_945747066.webp)
Chapter 6 Tutorials
MGS3520 Series User’s Guide
66
3
Click the
Save
link in the upper right corner of the web configurator to save your configuration
permanently.
Clients that attach to port 1, 2 or 3 and fail to authenticate with the RADIUS server now should be
in VLAN 200 and can access the Internet, but cannot communicate with devices in VLAN 1.
6.6 How to Do Port Isolation in a VLAN
You want to prevent communications between ports in a VLAN but still allow them to access the
Internet or network resources through the uplink port in the same VLAN. You use private VLAN to
do port isolation in a VLAN instead of assigning each port to a separate VLAN and creating a
different IP routing domain for each individual port.
In this example, you put ports 2 to 4 and 25 in VLAN 123 and create a private VLAN rule for VLAN
123 to block traffic between ports 2, 3 and 4.
Internet