Chapter 9
| General Security Measures
Port-based Traffic Segmentation
– 312 –
traffic-segmentation
This command enables traffic segmentation. Use the
no
form to disable traffic
segmentation.
Syntax
[
no
]
traffic-segmentation
Default Setting
Disabled
Command Mode
Global Configuration
Command Usage
◆
Traffic segmentation provides port-based security and isolation between
ports within the VLAN. Data traffic on the downlink ports can only be
forwarded to, and from, the designated uplink port(s). Data cannot pass
between downlink ports in the same segmented group, nor to ports which
do not belong to the same group.
◆
Traffic segmentation and normal VLANs can exist simultaneously within
the same switch. Traffic may pass freely between uplink ports in
segmented groups and ports in normal VLANs.
◆
When traffic segmentation is enabled, the forwarding state for the uplink
and downlink ports assigned to different client sessions is shown below.
Specifies whether or not traffic can be forwarded
between uplink ports assigned to different client
sessions
GC
Displays the configured traffic segments
PE
Table 60: Commands for Configuring Traffic Segmentation
(Continued)
Command
Function
Mode
Table 61: Traffic Segmentation Forwarding
Destination
Source
Session #1
Downlinks
Session #1
Uplinks
Session #2
Downlinks
Session #2
Uplinks
Normal
Ports
Session #1
Downlink Ports
Blocking
Forwarding
Blocking
Blocking
Blocking
Session #1
Uplink Ports
Forwarding
Forwarding
Blocking
Blocking/
Forwarding
*
Forwarding
Session #2
Downlink Ports
Blocking
Blocking
Blocking
Forwarding
Blocking
Session #2
Uplink Ports
Blocking
Blocking/
Forwarding
Forwarding
Forwarding
Forwarding
Normal Ports
Forwarding
Forwarding
Forwarding
Forwarding
Forwarding