Configuring Access Management with Port Isolation 335
Configuring Access Management with Port Isolation
Network Diagram Figure 117 Network diagram for access management and port isolation configuration
Networking and
Configuration
Requirements
Client PCs are connected to the Internet through Switch A. The IP address range
for organization 1 is 202.10.20.1/24 to 202.10.20.20/24; and the IP address
ranges for organization 2 are 202.10.20.25/24 to 202.10.20.50/24 and
202.10.20.55/24 to 202.10.20.65/24.
PCs of organization 1 are allowed to access the Internet through Ethernet 1/0/1
of Switch A.
PCs of organization 2 are allowed to access the Internet through Ethernet 1/0/2
of Switch A.
Both Ethernet 1/0/1 and Ethernet 1/0/2 belong to VLAN 1, and the IP address
of VLAN-interface 1 is 202.10.20.200/24.
PCs of organization 1 are isolated from those of organization 2 at Layer 2.
Applicable Products
Configuration Procedure # Enable access management on Switch A.
[SwitchA] am enable
Switch A
Switch B
Eth1/0/1
PC1_1 PC1_2 PC1_20
Internet
202.10.20.1/24̚202.10.20.20/24
Switch C
Eth1/0/2
PC2_1 PC2_2 PC2_37
Organization2
Organization1
202.10.20.25/24̚202.10.20.50/24
202.10.20.55/24̚202.10.20.65/24
Vlan-int1
202.10.20.200/24
Product series Software version Hardware version
Switch 5500 Release V03.02.04 All versions
Switch 5500G Release V03.02.04 All versions
Switch 4500 Release V03.03.00 All versions