端口隔离-二层隔离_端口隔离

需求

1、将pc1与pc2规划到vlan10中

2、vlan1与vlan2不能相互访问(阻止ARP)

3、同时能够访问vlan 10中的主机

知识储备

默认为:

隔离类型为:双向隔离

隔离模式:二层隔离

配置步骤

第一步:

系统视图

port -isolate mode l2//二层隔离

第二步:

接口视图下,将需要隔离端口分为一组

int g0/0/1

port-isolate enable group 10

详细配置内容

<sw1>display current-configuration  

#

sysname sw1

#

vlan batch 10 20

#

cluster enable

ntdp enable

ndp enable

#

drop illegal-mac alarm

#

dhcp enable

#

diffserv domain default

#

drop-profile default

#

ip pool dhcpvlan10

gateway-list 10.1.1.1

network 10.1.1.0 mask 255.255.255.0

lease day 10 hour 0 minute 0

dns-list 8.8.8.8

#

aaa

authentication-scheme default

authorization-scheme default

accounting-scheme default

domain default

domain default_admin

local-user admin password simple admin

local-user admin service-type http

#

interface Vlanif1

#

interface Vlanif10

ip address 10.1.1.1 255.255.255.0

dhcp select global

#

interface Vlanif20

ip address 20.1.1.1 255.255.255.0

#

interface MEth0/0/1

#

interface GigabitEthernet0/0/1

port link-type access

port default vlan 10

port-isolate enable group 10

#

interface GigabitEthernet0/0/2

port link-type access

port default vlan 10

port-isolate enable group 10

#

interface GigabitEthernet0/0/3

port link-type access

port default vlan 20

#

interface GigabitEthernet0/0/4

#

interface GigabitEthernet0/0/5

#

interface GigabitEthernet0/0/6

#

interface GigabitEthernet0/0/7

#

interface GigabitEthernet0/0/8

#

interface GigabitEthernet0/0/9

#

interface GigabitEthernet0/0/10

#

interface GigabitEthernet0/0/11

#

interface GigabitEthernet0/0/12

#

interface GigabitEthernet0/0/13

#

interface GigabitEthernet0/0/14

#

interface GigabitEthernet0/0/15

#

interface GigabitEthernet0/0/16

#

interface GigabitEthernet0/0/17

#

interface GigabitEthernet0/0/18

#

interface GigabitEthernet0/0/19

#

interface GigabitEthernet0/0/20

#

interface GigabitEthernet0/0/21

#

interface GigabitEthernet0/0/22

#

interface GigabitEthernet0/0/23

#

interface GigabitEthernet0/0/24

#

interface NULL0

#

ip route-static 0.0.0.0 0.0.0.0 20.1.1.2

#

user-interface con 0

idle-timeout 0 0

user-interface vty 0 4

#

return

<sw1>