10-25-2025 03:23 PM
I'm an not a network guy, understand some but the advanced stuff is above me and I know that. So I ask questions to help my understanding.
We would like to block east-west traffic, and I believe that port isolation, private vlans would help with that. The question is that we have Cisco phones and PCs sharing a drop. Is that something that can be done using port isolation - private vlans? The phones would need to be able to call a desk there in the game building on the same segment.
I'm sure there is a lot more to it, probably way over my head. We don't have a switch and licenses to test this and play with it. Would like to know if it is feasible before going that route.
Where is the Star Trek computer that I in my Scotty accent, can just say, Computer - block east-west traffic but let phone calls through...?
10-26-2025 08:48 AM
You can use technologies like Private VLANs (PVLANs) or port isolation to limit east-west traffic (that is, traffic between devices on the same VLAN). However, in your specific case — where phones and PCs share the same physical port — things become a bit tricky.
10-27-2025 07:48 AM
in below document yo can read
Do not configure private-VLAN ports on interfaces configured for these other features:
• Dynamic-access port VLAN membership
• Dynamic Trunking Protocol (DTP)
• IPv6 Security Group (SG)
• Port Aggregation Protocol (PAgP)
• Link Aggregation Control Protocol (LACP)
• Multicast VLAN Registration (MVR)
• Voice VLAN
• Web Cache Communication Protocol (WCCP)
so private vlans is not the way to go!
(documents for other switch models and IOS versions will probably sat the same)
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide