Configuring the ZyXEL ES-2108 Switch

I recently configured the ZyXEL ES-2108 switch.
Standard IP, login – admin, password – 1234.

I will give below examples of commands.

Let’s review the current configuration:

show running-config
show system-information

Now go to the configuration mode:


Change the administrator password:

admin-password PASSWORD
password PASSWORD

Turn on flood control and loop protection:


Let’s configure the VLAN to manage and assign the IP (I have a 207 vlan tag, 1 – uplink port):

vlan 207
  name core
  normal ""
  fixed 1
  forbidden 2-8
  untagged 2-8
  ip address default-management
  ip address default-gateway

Let’s configure VLAN for users (comes without a tag):

vlan 226
  name users
  normal ""
  fixed 1-8
  untagged 1-8

Configure the uplink port:

interface port-channel 1
  pvid 226

Configure the other client ports:

interface port-channel 2-8
bmstorm-limit 128
pvid 226

Set the time parameters:

time timezone 200
timesync server
timesync ntp

Configuring SNMP:

snmp-server set-community NAME
snmp-server trap-community NAME
snmp-server contact admin location LOCATION

Configure the logs:

syslog type system
syslog type interface
syslog type switch
syslog type aaa
syslog type ip

Let’s specify which IPs are allowed to administer the switch:

remote-management 1
remote-management 2
remote-management 1 start-addr end-addr service telnet ftp http icmp snmp ssh https
remote-management 2 start-addr end-addr service telnet ftp http icmp snmp ssh https

Exit the configuration mode:


To view mac-addresses, use the command:

show mac address-table

Save the settings:

write memory


Port isolation on the ZyXEL MES-3528 switch

On the test, I isolate the ports from each other, allowing traffic to go only to uplink (the port from which the Internet comes), I have it 25.

Let’s connect to the switch and see the current configuration:

show running-config

Now go into the configuration mode:


Isolate the necessary ports, except the uplink port:

interface port-channel 1-24,26-28
vlan1q port-isolation

Save the configuration:

write memory

The ports on which the vlan1q port-isolation command is written do not see other ports with the same command, but see the ports without it and the switch CPU. Ports without the command vlan1q port-isolation see the ports with it and without it.

See also:
Port isolation on Huawei switches
Configuring Protected Ports on Cisco