Configuring Port Isolation; Restrictions And Guidelines: Port Isolation Configuration; Assigning A Port To An Isolation Group - H3C S7500X Series Configuration Manual

Comware 7 layer 2 - lan switching
Hide thumbs Also See for S7500X Series:
Table of Contents

Advertisement

Configuring port isolation

The port isolation feature isolates Layer 2 traffic for data privacy and security without using VLANs.
Ports in an isolation group cannot communicate with each other. However, they can communicate
with ports outside the isolation group.
Restrictions and guidelines: Port isolation
configuration
Follow these guidelines when you configure port isolation:
When selective flood is enabled for a VXLAN VSI, port isolation does not affect selective flood if
you assign a site-facing interface of the VSI to an isolation group. An AC on the interface still
floods frames that match selective flood entries to all site-facing interfaces in the VXLAN,
including the interfaces in the same isolation group.
To enable selective flood for a MAC address in a VXLAN VSI, use the selective-flooding
mac-address command. For more information, see VXLAN Configuration Guide.
In an isolation group, a port associated with a VXLAN AC can still act as a trusted port to
forward DHCP packets to the other ports in the isolation group.
To configure a port as a trusted port in a DHCP snooping-enabled network, use the dhcp
snooping trust command. For more information, see DHCP snooping configuration in Layer
3—IP Services Configuration Guide.

Assigning a port to an isolation group

The device supports multiple isolation groups, which can be configured manually. The number of
ports assigned to an isolation group is not limited.
To assign a port to an isolation group:
Step
1.
Enter system view.
1.
Create an isolation
group.
2.
Enter interface view.
Command
system-view
port-isolate group group-id
Enter Layer 2 Ethernet
interface view:
interface interface-type
interface-number
Enter Layer 2 aggregate
interface view:
interface
bridge-aggregation
interface-number
1
Remarks
N/A
By default, no isolation groups exist.
The configuration in Layer 2
Ethernet interface view applies only
to the interface.
The configuration in Layer 2
aggregate interface view applies to
the Layer 2 aggregate interface and
its aggregation member ports. If the
device fails to apply the
configuration to the aggregate
interface, it does not assign any
aggregation member port to the
isolation group. If the failure occurs
on an aggregation member port, the
device skips the port and continues
to assign other aggregation member
ports to the isolation group.

Advertisement

Table of Contents
loading

Table of Contents