
Operation Manual – Port Isolation
H3C S9500 Series Routing Switches
Chapter 1 Port Isolation Configuration
1-1
Chapter 1 Port Isolation Configuration
When configuring port isolation, go to these sections for information you are interested
in:
z
Introduction to Port Isolation
z
Configuring an Isolation Group
z
Displaying and Maintaining Isolation Groups
z
Port Isolation Configuration Example
1.1 Introduction to Port Isolation
Usually, Layer 2 traffic isolation is achieved by assigning ports to different VLANs. To
save VLAN resources, port isolation is introduced to isolate ports within a VLAN,
allowing for great flexibility and security.
The idea is to isolate ports in the same VLAN by assigning them to a port isolation
group. For the isolated ports to communicate with a port outside isolation groups at
Layer 2, you are allowed to configure one uplink port for an isolation group. Layer-2
traffic of all the isolated ports can pass through the uplink port. In addition, to forward
traffic from the uplink port to an isolated port, you must ensure that the uplink port
carries the VLAN to which the isolated port belongs.
At present, the S9500 series switches support a maximum of 64 isolation groups and
the number of ports you can assign to an isolation group is not limited.
Note:
z
After you assign a link aggregation member port to an isolation group as an isolated
port, you can assign other member ports in the link aggregation group to the
isolation group as isolated ports but not as the uplink port. If the port is assigned to
the isolation group as the uplink port, you cannot assign other member ports to the
isolation group neither can you assign the other ports on the device to the link
aggregation group.
z
Port isolation isolates Layer 2 traffic but not Layer 3 traffic.
For ports belonging to different VLANs, Layer 2 traffic can pass from an isolated port to
the uplink port in the same isolation group unidirectionally but not in any other cases, as
shown in
Figure 1-1
.