Got it

Ways to isolate ports from each other on layer 2

Latest reply: Apr 23, 2019 14:21:54 197 1 0 0

Sometimes we want to isolate two interfaces from each other, so that the devices which connected to these interfaces can not access each other.

Some people may configure these two PCs into different networks and yes, that may work. But if these two PC are on the same network, how could we achieve that goal? Here we list of a few ways to do this.


As the most common and widely used way, VLAN may be the first way we think out when we are appointed this task.

As known, the interfaces in the different VLANs can not access each other through the layer 2. But there is a problem, which is the number of the VLAN. As the VLAN tag described, VLAN tag only contains 12 bits, which means that the maximum number of VLAN is 4096, in fact, there are a few VLANs that are reserved, so the usable VLANs are less than 4096.

So, the way to configure the VLAN to isolate the interface is not the best way.


MUX VLAN, which is called private VLAN in Cisco, can also be used to isolate the interfaces.

In MUX VLAN, there is a concept of separating the VLAN. In the separate VLAN, the interfaces are independent from each other, so we can add the interfaces which should isolate from each other into the separate VLAN.

Unlike the way of configuring the VLAN, the MUX VLAN will comsume more VLANs, because we have to configure the main VLAN and group VLAN. But if more than two interfaces exist (such as N interfaces) and both of them should be configured as isolation from each other, the way of configuring the VLAN will consume N VLANs. However, in MUX VLAN, only three VLANs are needed.

So, if more than two interfaces need to be configured to be isolated from each other, the MUX VLAN is a better way than VLAN.

3. Port isolation

Layer 2 port isolation can isolate interfaces on the same VLAN. That is, you only need to add interfaces to a port isolation group to implement Layer 2 isolation between these interfaces. 

Unlike the VLAN and MUX VLAN, port isolation doesn't waste VLANs. The configuration of the port isolation does not consume extra VLANs, making it the best way to do this. 

The port isolation only needs to add the interfaces which should be isolated from each other into the same group. In this group, the interfaces can not access each other, just like the separate VLAN in MUX VLAN.

  • x
  • convention:

Created Apr 23, 2019 14:21:54 Helpful(0) Helpful(0)

You can use MAC-Forced Forwarding or use S and C-Tag in Vlans to solve the 12 bits problem also.
View more
  • x
  • convention:


You need to log in to comment to the post Login | Register

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " Privacy."

My Followers

Login and enjoy all the member benefits


Huawei Enterprise Support Community
Huawei Enterprise Support Community
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Please bind your phone number to obtain invitation bonus.