port-isolation
interface/ethernet/switch/port-isolation
Syscap: musicswitch
Type: Directory
The CRS switches support flexible multi-level isolation features, which can be used for user access control, traffic engineering and advanced security and network management. The isolation features provide an organized fabric structure allowing the user to easily program and control the access by port, MAC address, VLAN, protocol, flow, and frame type. The following isolation and leakage features are supported:
- Port-level isolation
- MAC-level isolation
- VLAN-level isolation
- Protocol-level isolation
- Flow-level isolation
- Free combination of the above
Port-level isolation supports different control schemes on the source port and destination port. Each entry can be programmed with access control for either the source port or the destination port.
- When the entry is programmed with source port access control, the entry is.
applied to the ingress packets.
- When the entry is programmed with destination port access control, the entry
is applied to the egress packets.
| Flag | Name | Description |
|---|---|---|
| X | disabled | |
| D | dynamic | |
| I | invalid |
| Argument | Type | Description |
|---|---|---|
| ports | multi { array-id } | Isolated/leaked ports. |
| type | enum (src | dst) { src:0, dst:1 } | Lookup type of the isolation/leakage entry:
|
| forwarding-type | ubit (bridged, routed) | Matching traffic forwarding type on Cloud Router Switch. |
| traffic-type | ubit (unicast, multicast, broadcast) | Matching traffic type. |
| registration-status | ubit (known, unknown) | Registration status for matching packets. Known ones are present in UFDB and MFDB, and unknown ones are not. |
| protocol-type | ubit (arp, nd, dhcpv4, dhcpv6, ripv1) | Included protocols for isolation/leakage. |
| flow-id | num | |
| mac-profile | enum (promiscuous | isolated | community1 | community2) { promiscuous:0, isolated:1, community1:2, community2:3 } | Matching MAC isolation/leakage profile. |
| port-profile | num | Matching Port isolation/leakage profile. |
| vlan-profile | enum (promiscuous | isolated | community1 | community2) { promiscuous:0, isolated:1, community1:2, community2:3 } | Matching VLAN isolation/leakage profile. |
interface/ethernet/switch/port-isolation
Syscap: rbswitch
Type: Directory
| Flag | Name | Description |
|---|---|---|
| I | invalid |
| Argument | Type | Description |
|---|---|---|
| forwarding-override | multi { array-id, port: enum } |
| Read-only Argument | Type | Description |
|---|---|---|
| name | string | |
| switch | enum |