Configuring a Traffic Policy to Implement Intra-VLAN Layer 2 Isolation
Context
After VLANs are assigned, users in the same VLAN can communication with each other. If users in a VLAN need to be isolated unidirectionally or bidirectionally, configure a traffic policy. A traffic policy is configured by binding traffic classifiers to traffic behaviors. The switch classifies packets according to packet information, and associates a traffic classifier with a traffic behavior to reject the packets matching the traffic classifier, implementing intra-VLAN isolation.
The switch provides intra-VLAN Layer 2 isolation based on MQC and based on the ACL-based simplified traffic policy.
Pre-configuration Tasks
Before configuring a traffic policy to implement intra-VLAN Layer 2 isolation, perform the task of assign VLANs.
Procedure
- Configure MQC to implement intra-VLAN Layer 2 isolation.
Perform the following MQC configurations to implement intra-VLAN Layer 2 isolation:
- Specify permit or deny in the traffic behavior.
- Apply the traffic policy to a VLAN or an interface that allows the VLAN.
For details about how to configure MQC, see Configuring Packet Filtering in "Packet Filtering Configuration" in the S7700 and S9700 V200R011C10 Configuration Guide - QoS.
- Configure an ACL-based simplified traffic policy to implement intra-VLAN Layer 2 isolation.
For details about how to configure an ACL-based simplified traffic policy, see Configuring ACL-based Packet Filtering in "ACL-based Simplified Traffic Policy Configuration" in the S7700 and S9700 V200R011C10 Configuration Guide - QoS.