port isolation only on the first 24 ports (MS250)

sebas
Getting noticed

port isolation only on the first 24 ports (MS250)

Is there a hardware limitation for this feature to be enabled on port 25-48 on the MS250 ? 

I don't want to physically re-patch devices to be able to use this functionality 😞

 

 

 

12 Replies 12
SoCalRacer
Kind of a big deal

sebas
Getting noticed

I know, but i want to know why so it might be some software feature in the future ?

Nash
Kind of a big deal

I would:

 

  1. Make a wish on the switch page, so it goes to the right team.
  2. Contact your account manager and see if they've got any details.
  3. See if @MeredithW can get someone to come give us the low down. 🙂
PhilipDAth
Kind of a big deal
Kind of a big deal

This restriction has existed for many years.  So I suspect it is a hardware limitation.

 

Internally the 48 port switches are effectively two chips.  Each chip is a 24 port switch with an interconnection between them.

I would say the issue is what while you could enable port security on the second chip like the first - it wont work between the chips.  So people on the second chip wouldn't be able to talk with each other but could talk with anyone on the first switch.

Sounds unresovable.

BrechtSchamp
Kind of a big deal

Oh you had me worried there for a moment. I thought you were talking about the .1X access policies. But you're talking about port isolation. I'd try to avoid using the term "port security" for that to avoid confusion.

sebas
Getting noticed

indeed i mend port isolation ..

Changed the topic titel 🙂

LeoBac
Comes here often

Thanks for the detailed response.  Does this mean that the 48 port switches that do support isolation on all 48 ports use only one chip or is there something else they are doing to enable this?  I know you’re not the authority on port isolation but figured I’d ask in case you knew.  Thanks!

PhilipDAth
Kind of a big deal
Kind of a big deal

You can only configure port isolation on the first 24 ports.

cmr
Kind of a big deal
Kind of a big deal

@PhilipDAth I think @LeoBac is referring to 48 port MS35X switches and from our dashboard it does look like you can enable it on ports in the 30's.

If my answer solves your problem please click Accept as Solution so others can benefit from it.
LeoBac
Comes here often

Thank you @cmr @and thank you @PhilipDAth for your responses.  Cmr is correct, I’m asking if port isolation can be enabled for all 48 ports on the MS350s or above.  However the dashboard is deceiving.  The dashboard allows me to enable for all 48 ports for our MS225 even though it’s only supported on the first 24 ports.  @PhilipDAth , any other thoughts on this?  Thanks guys!

cmr
Kind of a big deal
Kind of a big deal

@LeoBac I've got some more MS355Xs on order, but they are only the 24 port ones...  No plans to be at the site with the 48 port versions until the new year.  @DarrenOC do you have any lying around?

If my answer solves your problem please click Accept as Solution so others can benefit from it.
thomasthomsen
Kind of a big deal

I see that the documentation for this has been updated (Last updatedApr 13, 2023).

Now it does not mention any special , ehhh, "conditions" for different models.

Will it now work, across all switches regardless of port density ? - do anyone know ?

 

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels