Explore the guide library · Switch selection and setup
Port-to-port forwarding restrictions and logical network membership are different controls that require their own tests.

Port isolation and VLANs can both appear in discussions about separating devices, but they do not mean the same thing. Understanding the difference helps avoid a configuration that blocks one path while leaving another unintended route available.
Read the port-isolation behavior
TP-Link’s switch configuration guide describes forwarding lists for isolated ports. The exact behavior depends on the switch and firmware. Determine which ports can exchange traffic and which uplink remains reachable in the proposed arrangement.
Understand VLAN membership separately
A VLAN places traffic into a logical network according to the configured membership and tagging rules. Communication between routed networks then depends on the router or firewall policy. The access point’s SSID mapping is another part of that path.
Write the actual requirement
For example, guest devices may need internet access while being unable to reach private computers or switch administration. State the permitted and prohibited relationships before choosing a feature. “Enable isolation” is not a complete design specification.
Test all relevant paths
- Between clients on separate switch ports.
- Between clients behind the same access point.
- From guests to private routed networks.
- From guests to device-management interfaces.
Use harmless resources you control and test from the actual client locations. A switch control may not govern traffic that never traverses the relevant switch ports.
Preserve administration access
Keep a supported management path and configuration backup while changing forwarding rules. On a shared installation, have the responsible administrator review the design and maintenance window.
After the change, record the expected outcomes and repeat them when adding switches or access points. Port isolation can be useful for a defined local forwarding requirement, while VLANs and routing policy serve broader segmentation roles. Choose and verify each control according to the path it actually governs rather than treating their names as interchangeable guarantees.
Sources and editorial notes
Sources checked 8–9 October 2026. Independent guidance and original illustrations; product comparisons use published specifications rather than hands-on benchmarks. Check the exact model, revision and regional documentation before changing settings.
- TP-Link: switch port isolation and forwarding lists
- NETGEAR: VLAN membership and tagging
- TP-Link: EAP wireless VLAN mapping