1-7
z
Enable the dynamic address binding support of IP Source Guard to filter packets received on a port
based on the source IP address and MAC address bindings created dynamically to prevent illegal
packets from passing through the port. For information about this feature, refer to
IP Source Guard
Configuration
in the
Security Volume
.
z
To save system resources, disable user bindings recording on the DHCP snooping trusted ports
that forward DHCP packets. For information about this feature, refer to
DHCP Configuration
in the
IP Services Volume
.
Configuring One-to-One VLAN Mapping
Perform one-to-one VLAN mapping on the corridor switches shown in
Figure 1-1
to use VLANs to
isolate different services of different users.
Configuring One-to-One VLAN Mapping
Configuration prerequisites
The CVLAN-to-SVLAN mappings have been planned.
Configuration procedure
Follow these steps to configure a one-to-one VLAN mapping:
To do...
Use the command...
Remarks
Enter system view
system-view
—
Create a VLAN
vlan
vlan-id
Create a CVLAN
and a SVLAN
Exit to system
view
quit
Required
By default, only the
default VLAN (VLAN 1)
exists.
Repeat these steps for
all CVLANs and SVLANs
involved in VLAN
mapping.
Configure an uplink policy to map the
CVLAN to the SVLAN
Refer to
Table 1-1
Required
Configure a downlink policy to map the
SVLAN to the original CVLAN
Refer to
Table 1-2
Required
Enter interface view of the downlink
port
interface interface-type
interface-number
—
Set the link type of the downlink port to
trunk
port link-type
trunk
Required
Configure the downlink port to permit
the specified CVLANs and SVLANs or
all VLANs to pass through
port trunk permit vlan
{
vlan-id-list
|
all
}
Required
By default, a trunk port
permits only VLAN 1 to
pass through.
Enable basic QinQ on the port
qing enable
Required
Apply the uplink policy to the inbound
direction of the downlink port
qos apply policy policy-name
inbound
Required
Apply the downlink policy to the
outbound direction of the downlink port
qos apply policy policy-name
outbound
Required
Содержание S7906E - Switch
Страница 82: ...1 4 DeviceA interface tunnel 1 DeviceA Tunnel1 service loopback group 1...
Страница 200: ...1 11 DeviceB display vlan dynamic No dynamic vlans exist...
Страница 494: ...ii Displaying and Maintaining Tunneling Configuration 1 45 Troubleshooting Tunneling Configuration 1 45...
Страница 598: ...ii...
Страница 1757: ...4 9...
Страница 1770: ...6 4...
Страница 2017: ...2 11 Figure 2 3 SFTP client interface...
Страница 2062: ...i Table of Contents 1 URPF Configuration 1 1 URPF Overview 1 1 What is URPF 1 1 How URPF Works 1 1 Configuring URPF 1 2...
Страница 2238: ...1 16 DeviceA cfd linktrace service instance 1 mep 1001 target mep 4002...
Страница 2442: ...2 4 Set the interval for sending Syslog or trap messages to 20 seconds Device mac address information interval 20...