- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
Port Based VLANs not isolated
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Port Based VLANs not isolated
I
Hi,
I'm trying to configure port based vlan on netgear m4300 8x8f. According to this tutorial : https://kb.netgear.com/29997/How-to-create-Layer-2-VLANs-on-NETGEAR-ProSAFE-Switches, but there is no isolation between subnet.
Consider this graphics, with A = 192.168.2.X subnet, B = 192.168.4.X subnet and C = 192.168.5.X subnet :
I want two VLANs : VLAN2 = A + B and VLAN3 = A + C, and a trunk link between A and the switch. So, I've configure port 1/0/9 and 1/0/11 in VLAN2 (untag) and port 1/0/13 and 1/0/11 in VLAN2 (untag) with the VLAN membership menu. After that, I've configure PVID = 2 / Vlan tag = 2 for 1/0/9 and PVID = 3 / Vlan tag = 3 for 1/0/13. But i still ping C from B and i don't understand why ...
Any advises will be welcome.
Best regards
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Re: Port Based VLANs not isolated
The router is where you need to implement policies to block inter-subnet traffic. Otherwise, a ping from B will go the router, which will happily forward it to C and back.
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Re: Port Based VLANs not isolated
Does your router support VLANs?
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Re: Port Based VLANs not isolated
@KrustyKwrote:
Thanks for the reply, is there any approach to isolate subnets with switch only ?
By definition and implying proper configuration, VLANs are isolated L2 networks. EIther you have some L3 routing in place (on a switch, on a router, on any host), interconnect the VLANs somehow, or there is a faulty device not properly handling a VLAN trunk (with tagged VLANs) creating an interconnection.