< Home

management-plane isolate enable

Function

The management-plane isolate enable command isolates service interfaces from the management interface.

The undo management-plane isolate enable command enables service interfaces to access the management interface.

By default, service interfaces can access the management interface.

Format

management-plane isolate enable

undo management-plane isolate enable

Parameters

None

Views

System view

Default Level

3: Management level

Usage Guidelines

Usage Scenario

To prevent attacks from service networks to the management network, run the management-plane isolate enable command to isolate service interfaces from the management interface. After a service interface receives packets destined for the management interface, it cannot send the packets to the management interface. The management interface, however, can still access service interfaces. This enhances network security.

Example

# Isolate service interfaces from the management interface.
<sysname> system-view
[sysname] management-plane isolate enable
Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >