03-08-2019 02:20 AM - edited 03-08-2019 02:25 AM
Hi
I need a Layer 2 Isolation for the guest vlan on some catalyst ws-c2960x switches (are connencted via trunk ports) for the customers Ubiquiti unifi APs.
Here are my config for the public wlan vlan, i need that the vlan 102 can only see the Gateway (ist on vlan 102 too) but no other devices on the same subnet. Vlan 30 and 101 are normal subnets without restrictions.
vlan 102 name WLAN Public !
interface GigabitEthernet1/0/15 description AP UniFi switchport trunk allowed vlan 30,101,102 switchport trunk native vlan 30 switchport mode trunk srr-queue bandwidth share 1 30 35 5 priority-queue out auto qos trust spanning-tree guard root !
Can anyone gibe me a example for my config how to do that?
Thank you in advance.
03-08-2019 03:54 AM
Hello
Just to config you wish vlan 102 users to be isolated from 30 & 101 correct?
03-08-2019 04:12 AM
No, the VLANs are seperated on the Firewall , my Goal is that the user in the public wlan (vlan102) can not see the other users devices (layer 2 Isolation) he should only able to Access the Gateway/Firewall. Guest Control is on the Controller and Access Points (Ubiquiti) active, now i Need this activated on the switch too.
I Need the same like the protected port only for a vlan.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide