03-Layer 2—LAN Switching Configuration Guide

HomeSupportSwitchesS6300 SeriesConfigure & DeployConfiguration GuidesH3C S6300 Switch Series Configuration Guides-Release 243x-6W10003-Layer 2—LAN Switching Configuration Guide
06-Port isolation configuration
Title Size Download
06-Port isolation configuration 58.64 KB

Configuring port isolation

The port isolation feature isolates Layer 2 traffic for data privacy and security without using VLANs.

Ports in an isolation group cannot communicate with each other. However, they can communicate with ports outside the isolation group.

Assigning a port to an isolation group

The device supports multiple isolation groups, which can be configured manually. The number of ports assigned to an isolation group is not limited.

To assign a port to an isolation group:

 

Step

Command

Remarks

1.      Enter system view.

system-view

N/A

2.      Create an isolation group.

port-isolate group group-number

By default, no isolation group exists.

1.      Enter interface view.

·          Enter Layer 2 Ethernet interface view:
interface interface-type interface-number

·          Enter Layer 2 aggregate interface view:
interface bridge-aggregation interface-number

·          The configuration in Layer 2 Ethernet interface view applies only to the interface.

·          The configuration in Layer 2 aggregate interface view applies to the Layer 2 aggregate interface and its aggregation member ports. If the device fails to apply the configuration to the aggregate interface, it does not assign any aggregation member port to the isolation group. If the failure occurs on an aggregation member port, the device skips the port and continues to assign other aggregation member ports to the isolation group.

2.      Assign the port to the specified isolation group.

port-isolate enable group group-number

By default, the port is not in any isolation group.

You can assign a port to at most one isolation group. If you execute the port-isolate enable group command multiple times, the most recent configuration takes effect.

 

Displaying and maintaining port isolation

Execute display commands in any view.

 

Task

Command

Display isolation group information.

display port-isolate group [ group-number ]

 

Port isolation configuration example

Network requirements

As shown in Figure 1, configure port isolation on the device to meet the following requirements:

·           The hosts can access the Internet.

·           The hosts cannot communicate with each other at Layer 2.

Figure 1 Network diagram

 

 

Configuration procedure

# Create isolation group 2.

<Device> system-view

[Device] port-isolate group 2

# Assign Ten-GigabitEthernet 1/0/1, Ten-GigabitEthernet 1/0/2, and Ten-GigabitEthernet 1/0/3 to isolation group 2.

[Device] interface ten-gigabitethernet 1/0/1

[Device-Ten-GigabitEthernet1/0/1] port-isolate enable group 2

[Device-Ten-GigabitEthernet1/0/1] quit

[Device] interface ten-gigabitethernet 1/0/2

[Device-Ten-GigabitEthernet1/0/2] port-isolate enable group 2

[Device-Ten-GigabitEthernet1/0/2] quit

[Device] interface ten-gigabitethernet 1/0/3

[Device-Ten-GigabitEthernet1/0/3] port-isolate enable group 2

Verifying the configuration

# Display information about isolation group 2.

[Device] display port-isolate group 2

 Port isolation group information:

 Group ID: 2

 Group members:

    Ten-GigabitEthernet1/0/1

    Ten-GigabitEthernet1/0/2

    Ten-GigabitEthernet1/0/3

The output shows that interfaces Ten-GigabitEthernet 1/0/1, Ten-GigabitEthernet 1/0/2, and Ten-GigabitEthernet 1/0/3 are assigned to isolation group 2. As a result, Host A, Host B, and Host C are isolated from each other at layer 2.

 

  • Cloud & AI
  • InterConnect
  • Intelligent Computing
  • Security
  • SMB Products
  • Intelligent Terminal Products
  • Product Support Services
  • Technical Service Solutions
All Services
  • Resource Center
  • Policy
  • Online Help
All Support
  • Become a Partner
  • Partner Resources
  • Partner Business Management
All Partners
  • Profile
  • News & Events
  • Online Exhibition Center
  • Contact Us
All About Us
新华三官网