No relevant resource is found in the selected language.

This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. Read our privacy policy>Search

Reminder

To have a better experience, please upgrade your IE browser.

upgrade

Configuration Guide - Interface Management

CloudEngine 12800 and 12800E V200R003C00

This document describes the interface management configuration, including basic interface configuration, Ethernet interface configuration, and logical interface configuration.

Rate and give feedback:
Huawei uses machine translation combined with human proofreading to translate this document to different languages in order to help you better understand the content of this document. Note: Even the most advanced machine translation cannot match the quality of professional translators. Huawei shall not bear any responsibility for translation accuracy and it is recommended that you refer to the English document (a link for which has been provided).
Example for Configuring Layer 2 Interface Isolation

Example for Configuring Layer 2 Interface Isolation

Networking Requirements

As shown in Figure 2-8, Server1, Server2, and Server3 belong to VLAN 10. Server1 and Server2 are not allowed to communicate with each other in VLAN10, but they are allowed to communicate with Server3.

Figure 2-8 Networking diagram of Layer 2 interface isolation configuration

Configuration Roadmap

The configuration roadmap is as follows:

  1. Add the interfaces to the specified VLAN.

  2. By default, interfaces are isolated at Layer 2 but can communicate at Layer 3. You can add interfaces to an isolation group to implement Layer 2 isolation between these interfaces.

Procedure

  1. Create VLAN 10 on Switch, and add interfaces to VLAN 10.

    <HUAWEI> system-view
    [~HUAWEI] sysname Switch
    [*HUAWEI] commit
    [~Switch] vlan 10
    [*Switch-vlan10] quit
    [*Switch] interface 10ge 1/0/1
    [*Switch-10GE1/0/1] port default vlan 10
    [*Switch-10GE1/0/1] quit
    [*Switch] interface 10ge 1/0/2
    [*Switch-10GE1/0/2] port default vlan 10
    [*Switch-10GE1/0/2] quit
    [*Switch] interface 10ge 1/0/3
    [*Switch-10GE1/0/3] port default vlan 10
    [*Switch-10GE1/0/3] quit
    [*Switch] commit

  2. Configure Layer 2 interface isolation.

    # Configure Layer 2 interface isolation for 10GE1/0/1.

    [~Switch] interface 10ge 1/0/1
    [~Switch-10GE1/0/1] port-isolate enable group 1
    [*Switch-10GE1/0/1] quit
    [*Switch] commit

    # Configure Layer 2 interface isolation for 10GE1/0/2.

    [~Switch] interface 10ge 1/0/2
    [~Switch-10GE1/0/2] port-isolate enable group 1
    [*Switch-10GE1/0/2] quit
    [*Switch] commit

  3. Verify the configuration.

    # Server1 and Server2 cannot communicate with each other.

    # Server1 and Server3 can communicate with each other.

    # Server2 and Server3 can communicate with each other.

Configuration Files

Configuration file of the switch

#
sysname Switch
#
vlan batch 10
#
interface 10GE1/0/1
 port default vlan 10 
 port-isolate enable group 1
#
interface 10GE1/0/2
 port default vlan 10 
 port-isolate enable group 1
#
interface 10GE1/0/3
 port default vlan 10 
#
return
Translation
Download
Updated: 2019-05-05

Document ID: EDOC1100004195

Views: 19078

Downloads: 37

Average rating:
This Document Applies to these Products

Related Version

Related Documents

Share
Previous Next