Example 2: L2 Traffic Transmission among Multiple VSYSs via Shared VSwitch

An enterprise deploys a Hillstone device in its network. VSYS-a is configured for Dept. A, and VSYS-b is configured for Dept. B. The interface ethernet0/0 is used by VSYS-a only and etherent0/7 is used by VSYS-b only. The interface etherenet0/3 is shared by Dept. A and Dept. B, and the two departments visit an Intranet server through ethernet0/3. See the topology below:

To meet the above requirement, the shared VSwitch and corresponding policy rules are needed. Below is the logical illustration.

Take the following steps:

Step 1: Configure ethernet0/3 of root VSYS.

  1. On the Navigation pane, click Configure > Network > Network to visit the Network page.
  2. Select ethernet0/3 from the interface list, and click Edit. In the Interface Configuration dialog, configure as below:
  3. Click OK to save the changes and return to the Network page.

Step 2: Create VSYS-a and VSYS-b, configure VSwitch1 to be a shared VSwitch, and l2-trust to be a shared zone.

  1. On the Navigation pane, click Configure > Network > VSYS to visit the VSYS page.
  2. Click New. In the Configuration dialog, configure as follows:
  3. Click OK.
  4. Click New. In the Configuration dialog, configure as follows:
  5. Click OK.
  6. Click Share Resource, and in the Share Resource dialog, configure as follows:
  7. Click Close to close the Share Resouce dialog.

Step 3: Configure VSYS-a.

  1. On the Navigation pane, click Configure > Network > VSYS to visit the VSYS page.
  2. Click VSYS-a in the VSYS list to enter the VSYS-a configuration page.
  3. On the Navigation pane of VSYS-a, click Configure > Network > Network to visit the Network page.
  4. Under the Task tab in the right pane, click VSwitch.
  5. In the VSwitch dialog, Click New.
  6. Type 2 into the VSwitch name box in the VSwitch Configuration dialog.
  7. Click OK to close the dialog.
  8. Click New on upper-left of the Zone list, and configure as follows:
  9. Click OK.
  10. Select ethernet0/0 from the interface list, and click Edit. In the Interface Configuration dialog, configure as below:
  11. Click OK to save the changes and return to the Network page.
  12. On the Navigation pane of VSYS-a, click Configure > Security > Policy to visit the Policy page.
  13. Click New. In the Policy Configuration dialog, configure as follows:
  14. Click OK to save the changes.

Step 4: Configure VSYS-b.

  1. On the Navigation pane, click Configure > Network > VSYS to visit the VSYS page.
  2. Click VSYS-b in the VSYS list to enter the VSYS-b configuration page.
  3. On the Navigation pane of VSYS-b, click Configure > Network > Network to visit the Network page.
  4. Under the Task tab in the right pane, click VSwitch.
  5. In the VSwitch dialog, Click New.
  6. Type 3 into the VSwitch name box in the VSwitch Configuration dialog.
  7. Click OK to close the dialog.
  8. Click New on upper-left of the Zone list, and configure as follows:
  9. Click OK.
  10. Select ethernet0/7 from the interface list, and click Edit. In the Interface Configuration dialog, configure as below:
  11. Click OK to save the changes and return to the Network page.
  12. On the Navigation pane of VSYS-b, click Configure > Security > Policy to visit the Policy page.
  13. Click New. In the Policy Configuration dialog, configure as follows:
  14. Click OK to save the changes.