
Port Isolation
Port Isolation – Configure Private VLAN
Microsemi PDS-408G Web Management User Guide Ver. 1.0.1, 03-2019
80
13
PORT ISOLATION
13.1
Port Isolation – Configure Private VLAN
13.1.1
General
Private VLAN
has nothing to do with traditional VLANs
, meaning that Private-VLAN ID can be
identical to VLAN-ID.
Private-VLAN filters outgoing destination port traffic. Packet received on port X can be sent only to
destination ports which are marked as part of port X group,
considering multiple PVLAN-ID table
rows configuration (union).
Private-VLAN does not affect unit management over IP.
Example
- PVLAN-ID2 = marked ports 1,5,6. PVLAN-ID3 = marked ports 1,6,8. All other ports are
unchecked.
As a result, ports-2,3,4,7,9,10,11 will not send any outgoing packets except for packets created
internally.
incoming traffic on port 1 will be sent only to ports 5,6,8.
Incoming traffic on port 5 will be sent only to ports 1,6.
Incoming traffic on port 6 will be sent to ports 1,5,8
Incoming traffic on port 8 will be sent to ports 1,6
Figure 13-1: Private VLAN Membership Configuration
13.1.2
Private VLAN - configuration parameters
•
Delete
- To delete a private VLAN entry, check this box. The entry will be deleted during the
next save.
•
PVLAN ID
- Indicates the ID of this Private-VLAN.
•
Port Members
- Used to show/select the unit Ethernet ports assigned to be members for this
specific Private-VLAN ID.
13.2
Port Isolation – Configure Port Isolation
13.2.1
General
Marked ports are prevented from sending packets to each other - isolated. However, they can
communicate normally with all the other Switch ports.
Example
- Marking ports 1,2 will block any traffic from port 1 to reach to port 2 and vice versa.
However, each one of them can communicate normally with ports 3-11