Separating the Management Plane from the Service Plane
You can separate the management plane from the service plane to improve management network security.
This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. Read our privacy policy>
You can separate the management plane from the service plane to improve management network security.
To improve network security, the device separates the traffic at the service and management planes by default. That is, unauthorized users cannot access the device through service interfaces, and attackers cannot attack the management network through the service network.
By default, the device separates the traffic at the service and management planes.
If you need to forward service packets through the management plane or access the device through service interface, disable the separation function. It is recommended that you restore the default configuration after you complete packet forwarding or device access to ensure management network security.
<HUAWEI> system-view [~HUAWEI] ip vpn-instance vpna [*HUAWEI-vpn-instance-vpna] quit [*HUAWEI] interface meth 0/0/0 [*HUAWEI-MEth0/0/0] ip binding vpn-instance vpna [*HUAWEI-MEth0/0/0] commit
<HUAWEI> system-view [~HUAWEI] ip vpn-instance vpnb [*HUAWEI-vpn-instance-vpnb] quit [*HUAWEI] interface 10ge 1/17/1 [*HUAWEI-10GE1/17/1] undo portswitch [*HUAWEI-10GE1/17/1] ip binding vpn-instance vpnb [*HUAWEI-10GE1/17/1] commit
Document ID: EDOC1000041694
Views: 59765
Downloads: 3623
Copyright © 2019 Huawei Technologies Co., Ltd. All rights reserved.