802.1Q settings help

Hello! Im trying to set up network isolation based on vlan tagging.

I have two virtual networks with VN_MAD 802.1Q selected and automatic vlan id. Both networks have the same bridge and phydev. I have changed to owner to different users.

When I attach these networks to two virtual machines owned by same users as the vnets, everything else works fine except network isolation. Both virtual machines can ping each other etc.

What am I doing wrong? How can I isolate the two virtual machines from each other?

Thanks in advance!

hello, and each network has separate gateway? if both points to same router, then they can be reachable via router.

They all have the same gateway. Do I need to make some virtual routers or what?

Thanks!

I think no, you can just filter it using firewall on that router.