Currently, Ethernet technology is widely used in the network. However, the existence of various network attacks (such as attacks on ARP, DHCP and other protocols) not only prevents legitimate network users from accessing network resources normally, but also poses a serious threat to network information security. Therefore, the security of Ethernet switching is becoming more and more important. This series introduces common Ethernet switching security technologies, including port isolation, port security, MAC address drift detection, storm control, port rate limit, MAC address table security, DHCP Snooping and IP Source Guard, to improve the understanding and awareness of Ethernet switching security.
As shown in the figure below, due to some business requirements, although PC1 and PC2 belong to the same VLAN, they are required not to communicate with each other at Layer 2 (but Layer 3 communication is allowed). PC1 and PC3 cannot communicate with each other under any circumstances, but the host in VLAN 3 can access the host in VLAN 2. So how to solve this problem? Port Isolation Technology OverviewThe port isolation function can be used to isolate ports in the same VLAN. Users only need to add ports to the isolation group to isolate the Layer 2 data between ports in the isolation group. The port isolation function provides users with a safer and more flexible networking solution. Port Isolation Technology Principle(1) Bidirectional isolation The interfaces in the same port isolation group are isolated from each other, but the interfaces in different port isolation groups are not isolated. Port isolation is only for the members of the port isolation group on the same device, and cannot be implemented for interfaces on different devices. (2) One-way isolation To isolate interfaces in different port isolation groups, you can configure unidirectional isolation between interfaces. By default, unidirectional port isolation is not configured. (3) L2 (Layer 2 isolation and Layer 3 interconnection) Broadcast packets in the same VLAN are isolated, but users on different ports can still communicate at Layer 3. By default, the port isolation mode is Layer 2 isolation and Layer 3 communication. (4) ALL (the second and third layers are isolated) Users on different ports in the same VLAN are completely isolated at Layer 2 and Layer 3 and cannot communicate. In the Layer 2 isolation and Layer 3 interconnection mode, enable the intra-VLAN Proxy ARP function on the VLANIF interface and run the arp-proxy inner-sub-vlan-proxy enable command to implement communication between hosts in the same VLAN. Port Isolation Configuration Commands(1) Enable port isolation By default, port isolation is disabled. If the group-id parameter is not specified, the default port isolation group is 1. (2) (Optional) Configuring port isolation mode By default, the port isolation mode is L2.
(3) Configuring unidirectional port isolation Use the am isolate command to configure unidirectional isolation between the current interface and the specified interface. After unidirectional isolation is configured between interface A and interface B, the packets sent by interface A cannot reach interface B, but the packets sent by interface B can reach interface A. By default, unidirectional port isolation is not configured. Port Isolation Configuration ExampleAs shown in the figure: PC1, PC2 and PC3 belong to VLAN 2. By configuring port isolation, PC3 can communicate with PC1 and PC2, but PC1 and PC2 cannot communicate with each other. The Switch configuration is as follows:
Port Isolation Configuration Verification(1) Use the display port-isolate group group-number command to view the ports in the port isolation group. (2) Verify that the host networks in the same port isolation group cannot communicate with each other. |
<<: What is a Fibre Channel Transceiver?
>>: How secure is HTTPS? A primer on the protocol that protects much of the web
It has been exactly one year since I last shared ...
A new report from IDC predicts that global privat...
Today, more and more organizations are embracing ...
Recently, China Unicom announced its full-year pe...
UCloud is a listed cloud computing company in Chi...
What kind of revolutionary impact will the Intern...
[[177568]] Allied Market Research forecasts that ...
For the vast majority of users, almost all of the...
On December 5-6, the 2017 Annual Meeting of the I...
This year, "new infrastructure" has bec...
In China, 5G has blossomed in the past year. Not ...
Recently, China Telecom Yunnan Company (Yunnan Te...
Keepalive is a high-availability component that i...
Recently, two major European operators, Vodafone ...
In the future, 5G networks are developing in the ...