what is normal port isolation ? i have only worked with ciscos private vlans , and they
use subdivided vlans within a primary vlan for the functionality inside the switch.
and switches that use PVID to configure same thing (async vlan)
which openwrt seems to belong to like linksys and netgear ?
In a nutshell, you can create secondary vlans with promiscious, isolated, and community ports. The promiscious can communicate with all other ports, while the community only with other ports of the same community.
Given the small amount of ports available on routers, this feature was not developed particularly. Maybe now that some managed switches are supported it will become a feature. Still, it is accommodating very specific scenarios and the same functionality can be achieved with intervlan routing and firewall rules.
second you need to do everything under br-lan ,
and not create bridges under every lan port.
third pay attention to image in "dsa and pvid usage examples"
It is 21.02 if your device haven't migrated to DSA, then you have swconfig between the physical port and cpu and DSA between the cpu and openwrt network config.
I really can’t say I am surprised.
How are the computer (router cpu) supposed to know what to do when your entire network multi vlan setup is untagged on every port?
To be honest your pictures doesn’t say anything and is only confusing.
Please show the network config file instead.
Did you remember to sync your new network settings with the dhcp and firewall settings?
You need to bridge eth ports , port1 port2 port3 , then enable vlan filtering under that bridge.
and do the vlan config in there , physcal ports on switch should be network devices
not vlans or other bridges.
seems you are creating vlans on eth0.X then bridging them under the bridge ,wrong sequence
reset, start fresh again , open br-lan , make sure your ports are showing up in
bridge ports section as port1 to 3, the go to bridge vlan filtering , make vlans and do the vlan-pvid setup there
ive resset all the setting
create VLANs on ports 1,2,3.
create Interfaces unmanaged put them in one zone
created new bridge and put all the ports in it
and still it doesnt work
And PS: as flygarn12 mentioned , first make sure the router you
are trying this with is on DSA not swconfig ,
you are trying to replicate DSA config after all
From the config and images , its looks like half and half.
Maybe you upgraded from 19.X or pre DSA config and kept
the config without a full reset , or something along the lines.