Inter-VLAN Layer 3 Isolation
After inter-VLAN Layer 3 connectivity is implemented between two VLANs, users from both VLANs can communicate. In some scenarios, communication between certain users needs to be restricted or only unidirectional communication allowed. For example, user hosts and servers often use unidirectional communication, and visitors to an enterprise are often allowed to access only the Internet or specific servers. In these scenarios, you need to configure inter-VLAN isolation.
Inter-VLAN isolation is often implemented using a traffic policy. You can define traffic classifiers on a switch to match packets with certain characteristics and associate the traffic classifiers with the permit or deny behavior in a traffic policy. The switch then permits or rejects the packets matching the traffic classifiers. This technology implements flexible inter-VLAN isolation.
The switch supports inter-VLAN Layer 3 isolation based on MQC and ACL-based simplified traffic policies. For details about MQC and ACL-based simplified traffic policies, see MQC Configuration and ACL-based Simplified Traffic Policy Configuration in the S12700 V200R010C00 Configuration Guide - QoS.