
15-2
Displaying Isolation Groups
To do… Use the command… Remarks
Display an isolation group and its
information
display port-isolate group
Available in any view
Port Isolation Configuration Example
Networking Requirement
z Users Host A, Host B, and Host C are connected to GigabitEthernet 0/0/1, GigabitEthernet 0/0/2,
and GigabitEthernet 0/0/3 of AC.
z AC is connected to an external network through GigabitEthernet 0/0/4.
z GigabitEthernet 0/0/1, GigabitEthernet 0/0/2, GigabitEthernet 0/0/3, and GigabitEthernet 0/0/4
belong to the same VLAN. It is desired that Host A, Host B, and Host C cannot communicate with
each other at Layer 2/Layer 3, but can access the external network.
Networking diagram
Figure 15-1 Network diagram for port isolation configuration
Internet
Host A Host B Host C
GE0/0/2
GE0/0/1
GE0/0/3
GE0/0/4
AC
Configuration procedure
# Add ports GigabitEthernet 0/0/1, GigabitEthernet 0/0/2 and GigabitEthernet 0/0/3 to the isolation
group.
<AC> system-view
[AC] interface GigabitEthernet0/0/1
[AC-GigabitEthernet0/0/1] port-isolate enable
[AC-GigabitEthernet0/0/1] quit
[AC] interface GigabitEthernet0/0/2
[AC-GigabitEthernet0/0/2] port-isolate enable
[AC-GigabitEthernet0/0/2] quit
[AC] interface GigabitEthernet0/0/3
[AC-GigabitEthernet0/0/3] port-isolate enable
[AC-GigabitEthernet0/0/3] return
# Display the information about the isolation group.
Komentáře k této Příručce