 
							
							
							Port-isolate默认仅在单台交换机内生效,跨交换机的隔离需通过VLAN 映射 + 端口隔离组联动或MUX VLAN实现。以下采用MUX VLAN方案(更灵活且易配置)。[H3C] vlan 20  # 主VLAN
[H3C-vlan20] mux-vlan
[H3C-vlan20] subordinate isolate vlan 21  # 创建隔离型从VLAN 21
[H3C-vlan20] quit
# 将PC2、PC5的端口加入隔离型从VLAN 21
[H3C] interface GigabitEthernet 1/0/1  # PC2连接的端口
[H3C-GigabitEthernet1/0/1] port access vlan 21
[H3C-GigabitEthernet1/0/1] quit
[H3C] interface GigabitEthernet 1/0/2  # PC5连接的端口
[H3C-GigabitEthernet1/0/2] port access vlan 21
[H3C-GigabitEthernet1/0/2] quit
# 交换机互联端口加入主VLAN 20(确保跨设备通信仅主VLAN转发)
[H3C] interface GigabitEthernet 1/0/24  # 与交换机2互联的端口
[H3C-GigabitEthernet1/0/24] port access vlan 20
[H3C-GigabitEthernet1/0/24] quit
[H3C] vlan 20  # 主VLAN
[H3C-vlan20] mux-vlan
[H3C-vlan20] subordinate isolate vlan 21  # 与交换机1的从VLAN保持一致
[H3C-vlan20] quit
# 将PC3的端口加入隔离型从VLAN 21
[H3C] interface GigabitEthernet 1/0/1  # PC3连接的端口
[H3C-GigabitEthernet1/0/1] port access vlan 21
[H3C-GigabitEthernet1/0/1] quit
# 交换机互联端口加入主VLAN 20
[H3C] interface GigabitEthernet 1/0/24  # 与交换机1互联的端口
[H3C-GigabitEthernet1/0/24] port access vlan 20
[H3C-GigabitEthernet1/0/24] quit
暂无评论
 
	 
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
暂无评论