Chapter 8
| General Security Measures
Port-based Traffic Segmentation
– 266 –
traffic-segmentation
This command enables traffic segmentation globally, or configures the uplink and
down-link ports for a segmented group of ports. Use the
no
form to disable traffic
segmentation globally.
Syntax
[
no
]
traffic-segmentation
[
uplink
interface-list
downlink
interface-list
]
uplink
– Specifies an uplink interface.
downlink
– Specifies a downlink interface.
interface-list
– One or more ports. Use a hyphen to indicate a consecutive
list of ports or a comma between non-consecutive ports.
Default Setting
Disabled globally
No segmented port groups are defined.
Command Mode
Global Configuration
Command Usage
◆
Traffic segmentation provides port-based security and isolation between ports
within the VLAN. Data traffic on the downlink ports can only be forwarded to,
and from, the designated uplink port(s). Data cannot pass between downlink
ports in the same segmented group, nor to ports which do not belong to the
same group.
◆
Any port can be defined as an uplink port or downlink port, but cannot be
configured to serve both roles.
◆
Traffic segmentation and normal VLANs can exist simultaneously within the
same switch. Traffic may pass freely between uplink ports in segmented groups
and ports in normal VLANs.
◆
Enter the
traffic-segmentation
command without any parameters to enable
traffic segmentation. Then set the interface members for segmented groups.
◆
Enter
no traffic-segmentation
to disable traffic segmentation and clear the
configuration settings for segmented groups.
Example
This example enables traffic segmentation, and then sets port 12 as the uplink and
ports 5-8 as downlinks.
Console(config)#traffic-segmentation
Console(config)#traffic-segmentation uplink ethernet 1/12
downlink ethernet 1/5-8
Console(config)#
Содержание EX-3524
Страница 2: ......
Страница 28: ...Figures 28 ...
Страница 34: ...Section I Getting Started 34 ...
Страница 58: ...Chapter 1 Initial Switch Configuration Setting the System Clock 58 ...
Страница 72: ...Chapter 2 Using the Command Line Interface CLI Command Groups 72 ...
Страница 156: ...Chapter 5 SNMP Commands Notification Log Commands 156 ...
Страница 164: ...Chapter 6 Remote Monitoring Commands 164 ...
Страница 218: ...Chapter 7 Authentication Commands Management IP Filter 218 ...
Страница 268: ...Chapter 8 General Security Measures Port based Traffic Segmentation 268 ...
Страница 292: ...Chapter 9 Access Control Lists ACL Information 292 ...
Страница 312: ...Chapter 10 Interface Commands Power Savings 312 ...
Страница 324: ...Chapter 11 Link Aggregation Commands Trunk Status Display Commands 324 ...
Страница 366: ...Chapter 15 Address Table Commands 366 ...
Страница 428: ...Chapter 17 VLAN Commands Configuring Voice VLANs 428 ...
Страница 572: ...Chapter 25 IP Interface Commands IPv6 Interface 572 ...
Страница 578: ...Section I Appendices 578 ...
Страница 594: ...Appendix C Customer Support Manuals 594 ...