![Huawei Quidway S3000-EI Series Operation Manual Download Page 271](http://html.mh-extra.com/html/huawei/quidway-s3000-ei-series/quidway-s3000-ei-series_operation-manual_169463271.webp)
Operation Manual - Network Protocol
Quidway S3000-EI Series Ethernet Switches
Chapter 5 Access Management Configuration
Huawei Technologies Proprietary
5-2
z
Configure port, IP address and MAC address binding
5.2.1 Enable Access Management Function
You can use the following command to enable access management function. Only after
the access management function is enabled will the access management features (IP
and port binding and Layer 2 port isolation) take effect.
Perform the following configuration in System view.
Table 5-1
Enable/Disable access management function
Operation
Command
Enable access management function
am enable
Disable access management function
undo am enable
By default, the system disables the access management function.
5.2.2 Configure Layer 2 Isolation between Ports
You can use the following command to set Layer 2 isolation on a port so as to prevent
the packets from being forwarded on Layer 2 between the specified port and some
other ports (group).
Perform the following configuration in Ethernet interface view.
Table 5-2
Configure Layer 2 isolation between ports
Operation
Command
Configure Layer 2 isolation between ports
am isolate
interface-list
Cancel Layer 2 isolation between ports
undo am isolate
interface-list
By default, the isolation port pool is null and the packets are allowed to be forwarded
between the specified port and all other ports on Layer 2.
5.2.3 Configure Port, IP Address and MAC Address Binding
Perform the following actions to bind the port, IP address and MAC address.
The system supports the following binding combination: Port+IP, Port+MAC,
Port+IP+MAC, and IP+MAC.
z
Port+IP binding: binding the packet’s receiving port and its source IP address. The
specified port will only allow the packet with specified IP address to pass;
meanwhile the packet with specified IP address can only pass through the
specified port.