In the configuration above, I already configure VLAN10, VLAN20 and VLAN30.
Question, how to configure routing between VLAN? like VLAN10 can also access to VLAN20 and VLAN30 back and forth?
"Short of the story is, you don't need routes. Just create the two VLANs that you want, both with IP addresses in separate subnets, and you will be able to ping each other."
When an isolated port transmits data, that data is mapped into an auxiliary VLAN. Data in the auxiliary VLAN will be mapped to the primary VLAN -only- for transmission to promiscuous ports. Promiscuous ports, in turn, transmit data into the primary VLAN. All ports can receive information in the primary VLAN.
Putting an otherwise isolated port into a community VLAN means that traffic it transmits will be mapped into both the auxiliary and the community VLAN. Community ports will receive data from both the primary and the community VLAN.
A given pair of ports will have bidirectional communication under the following conditions-
One or both are promiscuous, or...
Both are in the same PVLAN community.
VACL's are a completely different mechanism and provide some measure of per-packet (and usually protocol based) control of traffic bridged within a given VLAN. You might, for instance, block traffic on TCP/80 between all hosts within the VLAN while allowing all other traffic to pass.
It's possible to approximate the effects of PVLAN's by using a VACL but this tends to be somewhat fragile, difficult to manage and there are often inherent hardware limitations with which to contend (...highly dependent on platform).
Assuming you will use VL20 as your guest network, do the following:
Every switch that has guest devices on it should have VL 20 on it.
Configure the security profile on the WAG102 to use VL 20 for the guest SSID (check "enable 802.1 VLAN"). For the management profile, uncheck the Enable 802.1q VLAN box.
Make the AP ports on the switches VLAN 20 tagged and VL 1 untagged.
Make the port for the BT router VL 20 untagged.
If you have switch to switch connections, those ports should be set to VLAN 1 untagged and VL 20 tagged.
Everything else (your internal devices, management interface, etc) should be on VL 1 untagged ports.
Best Answer
I checked the user guide and nowhere does it mention inter-vlan routing: https://www.manualagent.com/hp/1920-24g-switch/users-manual/download
From the following link (1920-48g) https://www.reddit.com/r/networking/comments/62cs27/inter_vlan_routing_for_hpe_192048g/
"Short of the story is, you don't need routes. Just create the two VLANs that you want, both with IP addresses in separate subnets, and you will be able to ping each other."