H3C Low-End and Mid-Range Ethernet Switches Configuration Examples(V1.01)

HomeSupportSwitchesH3C S5500 Switch SeriesConfigure & DeployConfiguration ExamplesH3C Low-End and Mid-Range Ethernet Switches Configuration Examples(V1.01)
Table of Contents
Related Documents
41-Port Isolation Configuration Guide
Title Size Download
41-Port Isolation Configuration Guide 39 KB

Port Isolation

To isolate packets, you can add different ports to different VLANs. However, this will consume the limited VLAN resources. You can use the port isolation feature to isolate ports in the same VLAN. With port isolation, you can isolate ports within the same VLAN by assigning them to isolation groups. The port isolation function provides more secure and more flexible networking schemes.

Configuring Port Isolation

Network Diagram

Figure 1-1 Networking diagram for port isolation configuration

 

l          As shown in Figure 1-1, users Host A, Host B, and Host C are connected to GigabitEthernet 1/0/1, GigabitEthernet 1/0/2, and GigabitEthernet 1/0/3 of Device.

l          Device is connected to the Internet through GigabitEthernet 1/0/4.

l          GigabitEthernet 1/0/1, GigabitEthernet 1/0/2, GigabitEthernet 1/0/3, and GigabitEthernet 1/0/4 belong to the same VLAN. It is desired that Host A, Host B, and Host C cannot communicate with each other, but can access the Internet.

Applicable Product Matrix

Product series

Software version

Hardware version

S3610 series Ethernet switches

Release 5301

Release 5303

All versions

S5510 series Ethernet switches

Release 5301

Release 5303

All versions

S5500-SI series Ethernet switches

Release 1207

All versions except S5500-20TP-SI

Release 1301

S5500-20TP-SI

S5500-EI series Ethernet switches

Release 2102

All versions

S7500E series Ethernet switches

Release 6100

Release 6300

All versions

 

Configuration Procedure

# Add ports GigabitEthernet 1/0/1, GigabitEthernet 1/0/2, and GigabitEthernet 1/0/3 to the isolation group.

<Device> system-view

[Device] interface GigabitEthernet1/0/1

[Device-GigabitEthernet1/0/1] port-isolate enable

[Device-GigabitEthernet1/0/1] quit

[Device] interface GigabitEthernet1/0/2

[Device-GigabitEthernet1/0/2] port-isolate enable

[Device-GigabitEthernet1/0/2] quit

[Device] interface GigabitEthernet1/0/3

[Device-GigabitEthernet1/0/3] port-isolate enable

# Display the information about the isolation group.

<Device> display port-isolate group

 Port-isolate group information:

 Uplink port support: NO

 Group ID: 1

    GigabitEthernet1/0/1     GigabitEthernet1/0/2     GigabitEthernet1/0/3

Complete Configuration

#

interface GigabitEthernet1/0/1

 port-isolate enable

#

interface GigabitEthernet1/0/2

 port-isolate enable

#

interface GigabitEthernet1/0/3

 port-isolate enable

Configuration Guidelines

1)        Currently some devices support only one isolation group that is created automatically by the system as isolation group 1. You can neither remove the isolation group nor create other isolation groups on such devices.

2)        There is no restriction on the number of ports to be assigned to an isolation group.

3)        Bidirectional data transmission between a port within the isolation group and another port outside the isolation group is supported, provided that the two ports belong to the same VLAN, but that between ports within the isolation group is not supported.

4)        The port isolation feature supported on Ethernet switches of the S5500-SI and the S5500-EI series can isolate both Layer 2 and Layer 3 packets, but switches of other series listed in 102650  Applicable Product Matrix can only isolate Layer 2 packets.

  • Cloud & AI
  • InterConnect
  • Intelligent Computing
  • Security
  • SMB Products
  • Intelligent Terminal Products
  • Product Support Services
  • Technical Service Solutions
All Services
  • Resource Center
  • Policy
  • Online Help
All Support
  • Become a Partner
  • Partner Resources
  • Partner Business Management
All Partners
  • Profile
  • News & Events
  • Online Exhibition Center
  • Contact Us
All About Us
新华三官网