1
Configuring port isolation
About port isolation
The port isolation feature isolates Layer 2 traffic for data privacy and security without using VLANs.
Ports in an isolation group cannot communicate with each other. However, they can communicate
with ports outside the isolation group.
Assigning a port to an isolation group
About port assignment to an isolation group
The device supports multiple isolation groups, which can be configured manually. The number of
ports assigned to an isolation group is not limited.
Restrictions and guidelines
•
You can assign a port to only one isolation group. If you execute the
port-isolate enable
group
command multiple times, the most recent configuration takes effect.
•
The configuration in Layer 2 Ethernet interface view applies only to the interface.
•
The configuration in Layer 2 aggregate interface view applies to the Layer 2 aggregate interface
and its aggregation member ports. If the device fails to apply the configuration to the aggregate
interface, it does not assign any aggregation member port to the isolation group. If the failure
occurs on an aggregation member port, the device skips the port and continues to assign other
aggregation member ports to the isolation group.
Procedure
1.
Enter system view.
system-view
2.
Create an isolation group.
port-isolate group group-id
3.
Enter interface view.
{
Enter Layer 2 Ethernet interface view.
interface interface-type interface-number
{
Enter Layer 2 aggregate interface view.
interface bridge-aggregation interface-number
4.
Assign the port to the isolation group.
port-isolate enable group group-id
By default, the port is not in any isolation group.
Display and maintenance commands for port
isolation
Execute
display
commands in any view.
Summary of Contents for S6850 Series
Page 108: ...48 WGE1 0 3 32768 49153 50100 0x7b 0001 0001 0001 ACDEF...
Page 259: ...21 6 N A 200 6...
Page 337: ...ii...