TP-Link T1700X-16TS T1700X-16TSUN V1 CLI Reference Guide - Page 169

Port Isolation Commands

Page 169 highlights

Chapter 23 Port Isolation Commands Port Isolation provides a method of restricting traffic flow to improve the network security by forbidding the port to forward packets to the ports that are not on its forwarding port list. 23.1 port isolation Description The port isolation command is used to configure the forward port/LAG list of a port/LAG, so that this port/LAG can only communicate with the ports/LAGs on its list. To delete the corresponding configuration, please use no port isolation command. Syntax port isolation { [ te-forward-list te-forward-list ] [ po-forward-list po-forward-list ] } no port isolation Parameter te-forward-list -- The list of Ethernet ports. po-forward-list -- The list of LAGs. Command Mode Interface Configuration Mode (interface ten-gigabitEthernet / interface range ten-gigabitEthernet / interface port-channel / interface range port-channel) Example Set port 1, 2, 4 and LAG 2 to the forward list of port 1/0/5: T1700X-16TS(config)# interface ten-gigabitEthernet 1/0/5 T1700X-16TS(config-if)# port isolation te-forward-list 1/0/1-2,1/0/4 po-forward-list 2 Set all Ethernet ports and LAGs to forward list of port 1/0/2, namely restore to the default setting: T1700X-16TS(config)# interface ten-gigabitEthernet 1/0/2 T1700X-16TS(config-if)# no port isolation 155

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274

Chapter 23 Port Isolation Commands
Port Isolation provides a method of restricting traffic flow to improve the network security by
forbidding the port to forward packets to the ports that are not on its forwarding port list.
23.1 port isolation
Description
The
port isolation
command is used to configure the forward port/LAG list of a
port/LAG, so that this port/LAG can only communicate with the ports/LAGs on its
list. To delete the corresponding configuration, please use
no
port isolation
command.
Syntax
port
isolation
{
[
te-forward-list
te-forward-list
]
[
po-forward-list
po-forward-list
] }
no port isolation
Parameter
te-forward-list
—— The list of Ethernet ports.
po
-forward-list
—— The list of LAGs.
Command Mode
Interface Configuration Mode (interface ten-gigabitEthernet / interface range
ten-gigabitEthernet / interface port-channel / interface range port-channel)
Example
Set port 1, 2, 4 and LAG 2 to the forward list of port 1/0/5:
T1700X-16TS(config)# interface ten-gigabitEthernet
1/0/5
T1700X-16TS(config-if)#
port
isolation
te-forward-list
1/0/1-2,1/0/4
po-forward-list
2
Set all Ethernet ports and LAGs to forward list of port 1/0/2, namely restore to
the default setting:
T1700X-16TS(config)# interface ten-gigabitEthernet
1/0/2
T1700X-16TS(config-if)# no port isolation
155