300
C
HAPTER
17: N
ETWORK
P
ROTOCOL
O
PERATION
By default, the system disables the access management function.
Configuring the Access Management IP Address Pool Based on the Port
You can use the following command to set the IP address pool for access
management on a port. The packet whose source IP address is in the specified pool is
allowed to be forwarded on Layer 3 using the port of the Switch.
Perform the following configuration in Ethernet Port View.
By default, the IP address pools for access management on the port are null and all
the packets are permitted.
Note that if the IP address pool to be configured contains the IP addresses configured
in the static ARP at other ports, then the system prompts you to delete the static ARP
to make the later binding effective.
Configuring Layer 2 Isolation Between Ports
You can add a port to an isolation group using the following commands, and achieve
port-to-port isolation between this port and other ports of this group, that is, Layer 2
forwarding between the isolated ports is not available.
Perform the following configuration in Ethernet Port View.
By default, a port is not in an isolation group, that is Layer 2 forwarding is achievable
between this port and other ports.
Note that:
■
One unit only supports one isolation group. That is, a port in an isolation group on
a unit is isolated only from ports within this group, and not isolated from ports in
isolation groups on other units.
■
The port isolation feature is synchronous on the same unit within an aggregation
group. Note the following:
■
When a port in an aggregation group is added to, or removed from, an
isolation group, then all the other ports of this aggregation group on the same
unit are automatically added in or removed from this isolation group.
Disable access management function
undo am enable
Table 294
Configuring the Access Management IP Address Pool Based on the Port
Operation
Command
Configure the access management IP address pool
based on the port
am ip-pool
address_list
Cancel part or all of the IP addresses in the access
management IP address pool of the port
undo am ip-pool
{
all
|
address_list
}
Table 295
Configuring Layer 2 Isolation Between Ports
Operation
Command
Add a port to the isolation group
port isolate
Remove a port from the isolation group
undo port isolate
Table 293
Enabling/Disabling the Access Management Function
Operation
Command
Summary of Contents for 5500 SI - Switch - Stackable
Page 24: ...24 ABOUT THIS GUIDE...
Page 50: ...50 CHAPTER 1 GETTING STARTED...
Page 54: ...54 CHAPTER 2 ADDRESS MANAGEMENT CONFIGURATION...
Page 78: ...78 CHAPTER 3 PORT OPERATION...
Page 88: ...88 CHAPTER 4 XRN CONFIGURATION...
Page 122: ...122 CHAPTER 8 VLAN VPN CONFIGURATION...
Page 216: ...216 CHAPTER 15 SSH TERMINAL SERVICES...
Page 268: ...268 CHAPTER 16 IP ROUTING PROTOCOL OPERATION...
Page 308: ...308 CHAPTER 17 NETWORK PROTOCOL OPERATION...
Page 349: ...349...
Page 350: ...350 CHAPTER 18 MULTICAST PROTOCOL...
Page 522: ...522 CHAPTER 22 FILE SYSTEM MANAGEMENT...
Page 584: ...584 CHAPTER 30 PASSWORD CONTROL CONFIGURATION OPERATIONS...
Page 600: ...600 CHAPTER 31 MSDP CONFIGURATION...
Page 614: ...614 CHAPTER 32 CLUSTERING...
Page 670: ...670 CHAPTER C AUTHENTICATING THE SWITCH 5500 WITH CISCO SECURE ACS...