Configuring port isolation
Assigning access ports to different VLANs is a typical way to isolate Layer 2 traffic for data privacy and
security, but this approach is demanding on VLAN resources. To isolate Layer 2 traffic without using
VLANs, HP introduced the port isolation feature.
To use the feature, you assign ports to a port isolation group. Ports in an isolation group are called
―isolated ports.‖ An isolated port does not forward any Layer 2 traffic to any other isolated port on the
same switch, even if they are in the same VLAN. Still, an isolated port can communicate with any other
port outside the isolation group, provided that they are in the same VLAN.
The switch supports one isolation group called ―isolation group 1.‖ This isolation group is created
automatically and cannot be deleted. There is no limit on the number of member ports.
Configuring an isolation group
Assigning a port to the isolation group
To add a port to the isolation group:
Step...
1.
Enter system view
2.
Enter
interface
view or
port
group
view
3.
Assign the port or ports to the
isolation group as an isolated
port or ports
Displaying isolation groups
Task...
Display the isolation group
information on a single-isolation-
group device
Command...
system-view
Enter Ethernet
interface interface-
interface view
type interface-number
Enter Layer 2
interface bridge-
aggregate
aggregation interface-
interface view
number
Enter port group
port-group manual
view
port-group-name
port-isolate enable
Command...
display port-isolate group [ | { begin |
exclude | include } regular-expression ]
Remarks
—
Required
Use one of the commands:
In Ethernet interface view, the subsequent
configurations apply to the current port
In Layer 2 aggregate interface view, the
subsequent configurations apply to the
Layer 2 aggregate interface and all its
member ports
In port group view, the subsequent
configurations apply to all ports in the port
group
Required
No ports are added to the isolation group by
default
44
Remarks
Available in any view