Protected Port on Cisco Catalyst Switch

Hello Attila

It all depends on what your network requirements are. In general, in enterprise networks, VLANs that serve end users such as desktop workstations, would typically not need to communicate directly with each other. But this must be done carefully. In some environments, some users may share folders directly with each other. Also if you have a network printer, file server, or other shared device on the same subnet connected to the same switch, you must ensure that those too are on unprotected ports.

This feature is useful on small networks that are typically served by a single switch. It is not very scalable as the size of the network grows. It’s a quick and dirty way of ensuring that employees don’t have access to their neighbor’s PCs.

This feature isn’t so critical, especially because modern PCs typically have a firewall that would block any attempts at direction communication between devices, but it adds one more layer of protection.

As you suggest, this feature would not make sense in a data center environment where direct communication between servers is necessary.

Yes, in such a scenario, those devices would be able to communicate if they’re on different switches. This is because the protected port feature works at the switch level, not the VLAN level. As far as VSS goes I don’t have an answer to that, and I haven’t found any documentation that clarifies this. I don’t know if VSS will consider both switches as one in such a case. My feeling is that port protection will work on a VSS pair as if they were one physical switch, but unless you actually try it out, there’s no way to know. I don’t currently have access to two switches that support VSS, so I can’t test it out, but if someone does, please share your results here.

If you need to prevent communication between devices on different switches in the same VLAN, a more scalable solution is to use private VLANs. Private VLANs will allow you to block communication between multiple devices on the same VLAN even if they’re on different switches:

I hope this has been helpful!

Laz

1 Like

I think this is the same feature as it’s called as Port Isolation on TP-LINK switch or others.

Hello Tom

Yes, a protected port on a Cisco switch and Port Isolation on TP-Link (and other vendor switches) serve a similar purpose, but they may differ slightly in implementation or terminology depending on the vendor.

The Protected Port on a Cisco switch ensures that ports marked as “protected” cannot communicate directly with one another, even if they are on the same VLAN.

Port Isolation on TP-Link and other vendor switches is similar in that it also prevents isolated ports from communicating directly with each other. Like Cisco’s protected port feature, isolated ports can still communicate with non-isolated ports or uplink ports.

As Rene states in the lesson however:

The protected port feature is pretty cool, but it is also very limited. In another lesson, I will show you how to configure Private VLANS, which is basically the protected port on steroids.

I hope this has been helpful!

Laz

1 Like

every impressive! I didn’t expected I could get a reply. Thank you!

1 Like