Procedure:
Configuring unidirectional isolation on interfaces
1. Run:
system-view
The system view is displayed.
2. (Optional) Run:
port-isolate mode { l2 | all }
Interface isolation is configured.
By default, ports are isolated at Layer 2 but can communicate at Layer 3.
3. Run:
interface interface-type interface-number
The Ethernet interface view is displayed.
4. Run:
am isolate { interface-type interface-number }&<1-8>
Unidirectional isolation is configured on the Ethernet interface.
By default, the unidirectional isolation function is disabled.
Note:
If interface A is isolated from interface B unidirectionally, packets sent from interface A cannot reach interface B, but packets sent from interface B can reach interface A.
Configuring an interface isolation group:
1. Run:
system-view
The system view is displayed.
2. (Optional) Run:
port-isolate mode { l2 | all }
Interface isolation is configured.
By default, ports are isolated at Layer 2 but can communicate at Layer 3.
3. Run:
interface interface-type interface-number
The Ethernet interface view is displayed.
4. Run:
port-isolate enable [ group group-id ]
Interface isolation is enabled on the Ethernet interface.
By default, interface isolation is disabled.
Note:
Interfaces in an interface isolation group are isolated from each other, but interfaces in different interface isolation groups can communicate. If group-id is not specified, interfaces are added to interface isolation group 1.
Configuring management interface isolation.
1. Run:
system-view
The system view is displayed.
2. Run:
management-port isolate enable
Management interface isolation is enabled.
By default, management interfaces are not isolated from service interfaces.
Note:
The AC6005 does not support management interface isolation.
3. Run:
management-plane isolate enable
Service interfaces are isolated from the management interface.
By default, service interfaces can access the management interface
Note:
The AC6005 does not have an MEth interface; therefore, it does not support service interface access to the management interface.
https://support.huawei.com/enterprise/en/doc/EDOC1000154080?section=j008