Port Isolation Configuration; Configuring The Isolation Group - HP 5820X series Configuration Manual

Hide thumbs Also See for 5820X series:
Table of Contents

Advertisement

Port isolation configuration

Assigning access ports to different VLANs is a typical way to isolate Layer 2 traffic for data privacy and
security, but this approach is VLAN-resource demanding. To isolate Layer 2 traffic without using VLANs,
HP introduced the port isolation feature.
To use the feature, you assign ports to a port isolation group. Ports in an isolation group are called
isolated ports. An isolated port does not forward any Layer 2 traffic to any other isolated port on the
same switch, even if they are in the same VLAN. Still, an isolated port can communicate with any other
port outside the isolation group, provided that they are in the same VLAN.
The HP 5800 and the HP 5820X switch series support only one isolation group called isolation group 1.
This isolation group is created automatically and cannot be deleted. There is no limit on the number of
member ports.

Configuring the isolation group

To assign a port to the isolation group:
To do...
1.
Enter system view
2.
Enter
interface
view or
port
group
view
3.
Assign the port or
ports to the isolation
group
If the switch fails to apply the port-isolate enable command to a Layer 2 aggregate interface, it does not
assign any member port of the aggregate interface to the isolation group. If the failure occurs on a
member port, the switch can still assign other member ports to the isolation group.
Use the command...
system-view
Enter
interface interface-type
Ethernet
interface
interface-number
view
Enter
Layer-2
interface bridge-aggregation
aggregate
interface-number
interface
view
Enter port
port-group manual port-group-
group
name
view
port-isolate enable
Remarks
Required.
Use one of the commands.
To assign an Ethernet port to the isolation
group, enter Ethernet interface view.
To assign a Layer 2 aggregate interface
to the isolation group, enter Layer 2
aggregate interface view. The subsequent
configuration applies to both the Layer-2
aggregate interface and all its member
ports.
To assign multiple Ethernet ports to the
isolation group in bulk, enter port group
view.
Required.
The isolation group does not contain any
ports by default.
54

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

5800 series

Table of Contents