26
Introduction to Port
Isolation
Configuring Isolation
Groups
Adding a Port to the
Isolation Group
P
I
ORT
SOLATION
When configuring port isolation, go to these sections for information you are
interested in:
"Introduction to Port Isolation" on page 507
■
"Configuring Isolation Groups" on page 507
■
"Displaying and Maintaining Isolation Groups" on page 508
■
"Port Isolation Configuration Example" on page 508
■
To implement Layer 2 isolation, you can add different ports to different VLANs.
However, this will waste the limited VLAN resource. With port isolation, the ports
can be isolated within the same VLAN. Thus, you need only to add the ports to the
isolation group to implement Layer 2 isolation. This provides you with more secure
and flexible networking schemes.
Presently:
A device supports only one isolation group, which is created automatically by
■
the system as Isolation Group 1. The user can neither delete this isolation group
nor create any other isolation group.
There is no restriction on the number of ports to be added to an isolation
■
group.
n
When a port in an aggregation group is configured as the ordinary port for
■
some isolation group, the other ports of the aggregation group can be added
to the isolation group as ordinary ports.
For details of an aggregation group, refer to
■
page
345.
Port isolation is independent of the VLAN the port belongs to. For ports belonging
to different VLANs, Layer 2 data of each port is isolated. Within the same VLAN,
Layer 2 data can be forwarded between ports within the isolation group and ports
outside the isolation group.
Follow these steps to add a port to the isolation group
To do...
Enter system view
C
ONFIGURATION
"Link Aggregation Overview" on
Use the command...
system-view
Remarks
-