H3C WX3000 Series Unified Switches Switching Engine Configuration Guide-6W103

HomeSupportWirelessH3C WX3000 Series Unified SwitchesConfigure & DeployConfiguration GuidesH3C WX3000 Series Unified Switches Switching Engine Configuration Guide-6W103
10-Port Isolation Configuration
Title Size Download
10-Port Isolation Configuration 62.35 KB

 

l          The term switch used throughout this chapter refers to a switching device in a generic sense or the switching engine of a unified switch in the WX3000 series.

l          The sample output information in this manual was created on the WX3024. The output information on your device may vary.

 

Port Isolation Overview

Introduction to Port Isolation

Through the port isolation feature, you can add the ports to be controlled into an isolation group to isolate the Layer 2 data between each port in the isolation group. Thus, you can improve the network security and network in a more flexible way.

Currently, you can configure only one isolation group on a switch. The number of Ethernet ports an isolation group can accommodate is not limited.

 

The port isolation function is independent of VLAN configuration.

 

Port Isolation Configuration

Follow these steps to add an Ethernet port to an isolation group:

To do…

Use the command…

Remarks

Enter system view

system-view

Enter Ethernet port view

interface interface-type interface-num

Add the Ethernet port to the isolation group

port isolate

Required

By default, an isolation group contains no port.

 

l          When a member port of an aggregation group is added to an isolation group, the other ports in the same aggregation group are added to the isolation group automatically.

l          When a member port of an aggregation group is deleted from an isolation group, the other ports in the same aggregation group are deleted from the isolation group automatically.

 

Displaying and Maintaining Port Isolation

To do…

Use the command…

Remarks

Display the information about the Ethernet ports added to the isolation group.

display isolate port

Available in any view

 

Port Isolation Configuration Example

Network requirements

As shown in Figure 1-1:

l          PC 2, PC 3 and PC 4 are connected to GigabitEthernet 1/0/2, GigabitEthernet 1/0/3, and GigabitEthernet 1/0/4.

l          The switch connects to the Internet through GigabitEthernet 1/0/1.

l          It is desired that PC 2, PC 3 and PC 4 cannot communicate with each other.

Figure 1-1 Network diagram for port isolation configuration

 

Configuration procedure

# Add GigabitEthernet 1/0/2, GigabitEthernet 1/0/3, and GigabitEthernet 1/0/4 to the isolation group.

<device> system-view

System View: return to User View with Ctrl+Z.

[device] interface GigabitEthernet1/0/2

[device-GigabitEthernet1/0/2] port isolate

[device-GigabitEthernet1/0/2] quit

[device] interface GigabitEthernet1/0/3

[device-GigabitEthernet1/0/3] port isolate

[device-GigabitEthernet1/0/3] quit

[device] interface GigabitEthernet1/0/4

[device-GigabitEthernet1/0/4] port isolate

[device-GigabitEthernet1/0/4] quit

[device]

# Display the information about the ports in the isolation group.

[device] display isolate port

 Isolated port(s) on UNIT 1:

 GigabitEthernet1/0/2, GigabitEthernet1/0/3, GigabitEthernet1/0/4

 

  • Cloud & AI
  • InterConnect
  • Intelligent Computing
  • Security
  • SMB Products
  • Intelligent Terminal Products
  • Product Support Services
  • Technical Service Solutions
All Services
  • Resource Center
  • Policy
  • Online Help
All Support
  • Become A Partner
  • Partner Policy & Program
  • Global Learning
  • Partner Sales Resources
  • Partner Business Management
  • Service Business
All Partners
  • Profile
  • News & Events
  • Online Exhibition Center
  • Contact Us
All About Us
新华三官网