The invention provides a network security isolation method and apparatus. The apparatus comprises an outer end machine, an isolation card and an inner end machine; the outer end machine, the isolationcard and the inner end machine are connected in sequence; an external network interface module, an access control module, a file content filtering module, a virus scanning module and an outer end protocol stripping conversion module connected in sequence are arranged in the outer end machine; an electronic isolation component module is arranged in the isolation card; and an inner end protocol stripping conversion module, an IPSec/ HIP/SSL module and an inner network interface module connected in sequence are arranged in the inner end machine. According to the network security isolation methodand apparatus, DDoS defense, access control, file content filtering, virus scanning, protocol stripping conversion and IPSec/HIP/SSL decryption are cooperatively used; and security isolation data transmission of different levels of networks can be achieved, and the network security isolation method and apparatus have the advantages of wide application range, rich functions and reliable effect.