Access Management
Configuration
Operation Manual – Access Management
H3C S3600 Series Ethernet Switches-Release 1510
Chapter 1
1-1
Chapter 1 Access Management Configuration
1.1 Access Management Overview
One of the typical Ethernet access networking scenario is that the users access
external network through the Ethernet switches. In this case, the external network is
connected to the Ethernet switch. The Ethernet switch connects to the Hubs, each of
which centralizes several PCs. The following figure illustrates the networking scenario.
Figure 1-1 Typical Ethernet access networking scenario
If not-so-many users are connected to the switch, the ports allocated to different
enterprises need to belong to the same VLAN in the light of cost. Every enterprise is
allocated to the fixed IP address range simultaneously. Only those IP addresses in the
fixed IP address range can be accessed to external networks from the port. Different
organizations should be isolated considering security. All these requirements can be
achieved with the access management function by the Ethernet switches, specifically,
binding a port with IP addresses and L2 isolation between ports. See
Figure 1-1.
In the figure, organization 1 and organization 2 belong to the same VLAN, which are
connected to the external networks via an Ethernet switch. The IP addresses
202.10.20.1 ~ 202.10.20.20 are allocated to organization 1, that is, they are bound to
the port 1. On the PCs with IP addresses in this range can be connected to external
networks. The IP addresses 202.10.20.21 ~ 202.10.20.50 are allocated to organization
2, or bound to the port 2.