HP 6125G HP 6125G & 6125G/XG Blade Switches Layer 2 - LAN Switching Co - Page 57

Configuring port isolation, Assigning a port to the isolation group

Page 57 highlights

Configuring port isolation Port isolation enables isolating Layer 2 traffic for data privacy and security without using VLANs. You can also use this feature to isolate the hosts in a VLAN from one another. To use the feature, assign ports to a port isolation group. Ports in an isolation group are called "isolated ports." One isolated port cannot forward Layer 2 traffic to any other isolated port on the same switch, even if they are in the same VLAN. An isolated port can communicate with any port outside the isolation group if they are in the same VLAN. The switch series supports only one isolation group "isolation group 1." The isolation group is automatically created and cannot be deleted. There is no limit on the number of member ports. Assigning a port to the isolation group Step 1. Enter system view. 2. Enter interface view. Command system-view • Enter Ethernet interface view: interface interface-type interface-number • Enter Layer 2 aggregate interface view: interface bridge-aggregation interface-number 3. Assign the port or ports to the isolation group as an isolated port-isolate enable port or ports. Remarks N/A Use one of the commands. • In Ethernet interface view, the subsequent configurations apply to the current port. • In Layer 2 aggregate interface view, the subsequent configurations apply to the Layer 2 aggregate interface and all its member ports. No ports are added to the isolation group by default. Displaying and maintaining the isolation group Task Display isolation group information. Command display port-isolate group [ | { begin | exclude | include } regular-expression ] Remarks Available in any view Port isolation configuration example Network requirements As shown in Figure 11, Host A, Host B, and Host C are connected to GigabitEthernet 1/0/1, GigabitEthernet 1/0/2, and GigabitEthernet 1/0/3 of Device, and Device is connected to the Internet through GigabitEthernet 1/0/4. All these ports are in the same VLAN. Configure Device to provide Internet access for all the hosts and isolate them from one another. 48

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231

48
Configuring port isolation
Port isolation enables isolating Layer 2 traffic for data privacy and security without using VLANs. You can
also use this feature to isolate the hosts in a VLAN from one another.
To use the feature, assign ports to a port isolation group. Ports in an isolation group are called "isolated
ports." One isolated port cannot forward Layer 2 traffic to any other isolated port on the same switch,
even if they are in the same VLAN. An isolated port can communicate with any port outside the isolation
group if they are in the same VLAN.
The switch series supports only one isolation group "isolation group 1." The isolation group is
automatically created and cannot be deleted. There is no limit on the number of member ports.
Assigning a port to the isolation group
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter interface view.
Enter Ethernet interface view:
interface
interface-type
interface-number
Enter Layer 2 aggregate
interface view:
interface bridge-aggregation
interface-number
Use one of the commands.
In Ethernet interface view, the
subsequent configurations
apply to the current port.
In Layer 2 aggregate interface
view, the subsequent
configurations apply to the
Layer 2 aggregate interface
and all its member ports.
3.
Assign the port or ports to the
isolation group as an isolated
port or ports.
port-isolate enable
No ports are added to the isolation
group by default.
Displaying and maintaining the isolation group
Task
Command
Remarks
Display isolation group
information.
display port-isolate group
[
|
{
begin
|
exclude
|
include
}
regular-expression
]
Available in any view
Port isolation configuration example
Network requirements
As shown in
Figure 11
, Host A, Host B, and Host C are connected to GigabitEthernet 1/0/1,
GigabitEthernet 1/0/2, and GigabitEthernet 1/0/3 of Device, and Device is connected to the Internet
through GigabitEthernet 1/0/4. All these ports are in the same VLAN.
Configure Device to provide Internet access for all the hosts and isolate them from one another.