OLT PON port isolation blocks Layer-2 traffic between ONUs and between PON ports; uplink isolation stops a PON-side broadcast storm from flooding the BRAS or core. Together with VLAN they are the base of FTTH subscriber separation and carrier compliance. Rayin's Mini GPON OLT L102P applies PON port isolation and rate-limits uplink broadcast per port, so a single bad ONU or a looped branch stays contained instead of taking down the whole uplink.

GPON downstream shares 2.488 Gbps (XGS-PON is 10 Gbps symmetric, ITU-T G.9807.1); one PON port's traffic is everyone's, so lateral isolation matters.
Downstream is encrypted with AES-128 (G.984.3) to stop eavesdropping — but encryption does not stop subscribers from seeing each other at Layer 2. That is what PON isolation adds.
Uplink isolation caps broadcast, unknown unicast, and multicast heading to the core, so one port's storm cannot saturate the shared 2.488 Gbps downstream.
The standard combo is PON isolation + uplink isolation + VLAN (802.1Q) + storm control — none of the four works fully alone.
An OLT faces two directions. Downward it serves many PON ports — each a tree hanging dozens to over a hundred ONUs. Upward it has uplink ports (GE/10GE) toward the BRAS or core. "Isolation" looks at both ends:
PON isolation: the OLT stops Layer-2 frames from passing directly between PON ports, and at the strictest setting even between ONUs under the same PON port.
Uplink isolation: the OLT gates broadcast and unknown traffic between the PON side and the uplink side, so one side's storm cannot pour into the other.
Note this is different from "port isolation on a single ONU" — that is the ONU managing its own downstream devices. This article is about isolation at the OLT central office level.
GPON broadcasts its 2.488 Gbps downstream (XGS-PON 10 Gbps up and down per G.9807.1), and every ONU on a PON port hears the same beam, decrypting only its own share with AES-128 (G.984.3). But at the Layer-2 forwarding level, if the OLT does not isolate, ONUs across PON ports — or even under one port — can "see" each other: household A's broadcast and ARP reach household B. That opens the door to freeloading, piggyback Wi-Fi, and lateral attacks.
With PON port isolation on, the OLT's forwarding table simply does not forward Layer-2 frames between PON ports or between ONUs by default. Any user-to-user traffic must go up through a router (Layer 3), cutting direct peer connection at the source.
If the PON side throws a broadcast storm, a loop, or an ONU spews unknown unicast, an un-isolated uplink ships all of it to the BRAS and core — filling the upstream bandwidth and dragging down unrelated services. In reverse, a core-side broadcast or multicast blast, if copied blindly down every PON port, wastes the already-shared 2.488 Gbps downstream.
Uplink isolation puts a gate on that path: PON-side broadcast and unknown traffic does not go up (or is rate-limited), and uplink-side broadcast is not pushed down indiscriminately — it forwards only inside the needed VLAN or multicast group.
1. Subscriber-to-subscriber isolation, lateral attack blocked. Different homes in one building or one hotel sit in independent Layer-2 domains; household A cannot scan household B's devices. ARP spoofing, internal lateral movement, and cross-house ransom spread are all stopped at the OLT.
2. Smaller broadcast domain, cleaner link. Isolation confines broadcast to its own PON port or even its own ONU, so it never floods the whole network; the shared downstream is left for real traffic.
3. Core protected, one fault contained. Uplink isolation keeps one PON port's abnormal traffic away from the BRAS, so a single branch problem does not bring down the whole OLT's uplink.
4. Compliance made easy. Carrier RFQs and security grading require "subscriber isolation" and "separate service and management planes." PON isolation + uplink isolation + VLAN is the most direct compliant combination.
FTTH multi-dwelling (apartments). One building, many ONUs on one OLT — PON isolation makes neighbors invisible to each other, ending private bridging and piggyback Wi-Fi, and stopping one infected home from hitting the whole block.
Hotel / office multi-tenant. PON ports per floor or per tenant, isolated plus a VLAN per tenant — the network behaves as if each were independent; no rewiring when a tenant leaves.
Enterprise campus, one network. Put finance, production, and guest ONUs on different PON ports with isolation, so the sensitive domain is not exposed to others — internal zoning satisfied.
Carrier BRAS protection against storms. Uplink isolation blocks PON-side broadcast and loops from climbing; BRAS uplink stays stable, critical during cutovers.
Multicast / IPTV control. Uplink isolation plus multicast VLAN pushes IPTV streams only to subscribed PON ports, not eating other ports' downstream.

Step 1 — Plan VLANs first. Assign one VLAN per user or per service, and split each ONU and each building into its own broadcast domain. VLAN draws the boundary; isolation decides whether domains talk.
Step 2 — Enable PON port isolation. On a Rayin OLT (such as the 2-port Mini GPON OLT L102P), turn on PON port isolation and per-user isolation so ONUs under different ports — and strictly, under the same port — do not forward to each other at Layer 2.
Step 3 — Add uplink storm control. On the uplink port set broadcast/unicast rate limits and storm control; keep the management VLAN separate from the service VLAN. Isolation is set centrally on the OLT — do not rely on the ONU to isolate itself.
Is PON isolation the same as ONU port isolation? No. ONU port isolation is the user's own router/ONU managing devices behind one ONU. PON isolation is OLT central-office level, governing between ONUs and between PON ports. Both levels on is the complete picture.
With PON isolation on, can users still reach each other? Layer 2 is blocked, but Layer 3 routing can pass traffic. Neighbors are isolated by default; real need-to-talk (a shared printer, say) is allowed by an upper-layer routing policy — safer than direct L2 bridging.
Will uplink isolation block normal service too? No. It targets only broadcast, unknown unicast, and unauthorized flooding; unicast service flows forward normally by MAC or route. With VLAN and storm-control thresholds, normal traffic is untouched.
GPON downstream is already encrypted — why still isolate? AES-128 (G.984.3) stops someone from listening to another's downstream light. PON isolation stops users from connecting to each other at Layer 2. One is against eavesdropping, the other against lateral connection — different jobs.
Which comes first, isolation or VLAN? Configure both. VLAN sets the broadcast-domain boundary; isolation sets whether domains inter-communicate. Either one alone is incomplete — plan VLANs, then turn on the matching isolation on the OLT.
Written by Sara, Customer Manager at Rayin — over 10 years in communications, focused on helping ISPs validate and maintain PON and industrial-switch networks for emerging markets.
About Rayin → https://www.szrayin.com/Profile/