Hi
I would think that this will depend on the setting:
are the networks / devices in these networks isolated or to they share same spaces
port isolation might provide more guarantees from security point of view
vlan are more flexible
kind of port isolation dictates complexity of configuration: on router is simpler while on switch, requires more configuration
In general I would go for vlans, since you have the hardware for it (CSS3xx) and is more flexible.
Note that the 4011 doesn't doe vlan filtering in hardware.
thx for answer!
devices are on separate floors if you think this and each ethernet socket has it's own room
I've tried to configure port isolation only on router yet, how big difference is to do it on switches?! I dont have it yet ..
what do you mean by "Note that the 4011 doesn't doe vlan filtering in hardware."? It could make this any trouble? Or it's just for info?