08-05-2023 08:06 PM
I’m interested in implementing Private VLANs for the purpose of isolating guest Wi-Fi users from one another. We use Ubiquiti APs that gave guest isolation enabled but only for users connected to the same access point. In theory an Isolated Private VLAN should prevent them from communicating with anybody on the Guest Wi-Fi network via other APs on different ports, BUT the APs also host other SSIDs and need traffic from regular VLANs. Am I allowed to configure the AP ports as Trunks or do physical switch ports need to be dedicated to PVLAN usage via port types?
08-05-2023 09:01 PM
@wezza2 hi, my personal idea is you can use normal guest vlan here. no need to use private VLANs. you can sperate Guest VLAN and other VLANS at layer 3 level and using L3 filtering with ACL/Firewall/etc.
08-06-2023 04:51 PM
I guess you are thinking about connecting an AP to a private vlan isolated port. It will not work. Isolated ports are access ports. They cannot be defined as trunks. Also, a private vlan is a single subnet network.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide