We're currently discussing the use of port isolation for security reasons for a customer. They want to minimize the effect of a possible malware incident.
They have a setup, where they connect many of the network clients through the internal switch if IP phones.
I was just wondering, whether port isolation would break internal SIP calls between the IP phones.
From what I know, SIP initiates direct connections between the phones after they've got corresponding IP information from the SIP server.
Is there a way to make an exception from port isolation for single VLANs?
Or would the customer need to implement something like a SIP proxy?