溫馨提示×

您好,登錄后才能下訂單哦!

密碼登錄×
登錄注冊(cè)×
其他方式登錄
點(diǎn)擊 登錄注冊(cè) 即表示同意《億速云用戶服務(wù)條款》

Protected ports

發(fā)布時(shí)間:2020-07-08 02:56:57 來(lái)源:網(wǎng)絡(luò) 閱讀:503 作者:流云飛逝 欄目:安全技術(shù)

在某些特殊需求下,需要禁止同臺(tái)交換機(jī)上相同VLAN 的主機(jī)之間通信,但又不能將這些不能通信的主機(jī)劃到不同VLAN,因?yàn)檫€需要和VLAN中的其它主機(jī)通信,只是不能和部分主機(jī)通信。這個(gè)特性可以實(shí)現(xiàn)這種需求.


Protected ports have these features:

  A protected port does not forward any traffic (unicast, multicast, or broadcast) to any other port that is also a protected port. Data traffic cannot be forwarded between protected ports at Layer 2; only control traffic, such as PIM packets, is forwarded because these packets are processed by the CPU and forwarded in software. All data traffic passing between protected ports must be forwarded through a Layer 3 device.

  Forwarding behavior between a protected port and a nonprotected port proceeds as usual.


You can configure protected ports on a physical interface (for example, Gigabit Ethernet port 1) or an EtherChannel group (for example, port-channel 5). When you enable protected ports for a port channel, it is enabled for all ports in the port-channel group.


Do not configure a private-VLAN port as a protected port. Do not configure a protected port as a private-VLAN port. A private-VLAN isolated port does not forward traffic to other isolated ports or community ports. For more information about private VLANs


注:這個(gè)feature只在單臺(tái)交換機(jī)上有效. 


sw1(config-if)#switchport protected    配置了這個(gè)特性的端口不能互訪.但能與其他端口訪問(wèn).


向AI問(wèn)一下細(xì)節(jié)

免責(zé)聲明:本站發(fā)布的內(nèi)容(圖片、視頻和文字)以原創(chuàng)、轉(zhuǎn)載和分享為主,文章觀點(diǎn)不代表本網(wǎng)站立場(chǎng),如果涉及侵權(quán)請(qǐng)聯(lián)系站長(zhǎng)郵箱:is@yisu.com進(jìn)行舉報(bào),并提供相關(guān)證據(jù),一經(jīng)查實(shí),將立刻刪除涉嫌侵權(quán)內(nèi)容。

AI