![Accton Technology 24/48 10/100 Ports + 2GE Management Manual Download Page 430](http://html1.mh-extra.com/html/accton-technology/24-48-10-100-ports-2ge/24-48-10-100-ports-2ge_management-manual_3749286430.webp)
Command Line Interface
4-188
4
Configuring Private VLANs
Private VLANs provide port-based security and isolation between ports within
the assigned VLAN. This switch supports two types of private VLANs: primary/
secondary associated groups, and stand-alone isolated VLANs. A primary VLAN
contains promiscuous ports that can communicate with all other ports in the private
VLAN group, while a secondary (or community) VLAN contains community ports
that can only communicate with other hosts within the secondary VLAN and with any
of the promiscuous ports in the associated primary VLAN. Isolated VLANs, on the
other hand, consist a single stand-alone VLAN that contains one promiscuous port
and one or more isolated (or host) ports. In all cases, the promiscuous ports are
designed to provide open access to an external network such as the Internet, while
the community or isolated ports provide restricted access to local users.
Multiple primary VLANs can be configured on this switch, and multiple community
VLANs can be associated with each primary VLAN. One or more isolated VLANs
can also be configured. (Note that private VLANs and normal VLANs can exist
simultaneously within the same switch.)
This section describes commands used to configure private VLANs.
To configure primary/secondary associated groups, follow these steps:
1.
Use the
private-vlan
command to designate one or more community VLANs
and the primary VLAN that will channel traffic outside of the community groups.
2.
Use the
private-vlan association
command to map the community VLAN(s) to
the primary VLAN.
Table 4-60 Private VLAN Commands
Command
Function
Mode
Page
Edit Private VLAN Groups
private-vlan
Adds or deletes primary and secondary VLANs
VC
4-189
private-vlan association
Associates a secondary VLAN with a primary VLAN
VC
4-190
Configure Private VLAN Interfaces
switchport mode
private-vlan
Sets an interface to host mode or promiscuous mode
IC
4-191
switchport private-vlan
host-association
Associates an interface with a secondary VLAN
IC
4-191
switchport private-vlan
isolated
Associates an interface with an isolated VLAN
IC
4-192
switchport private-vlan
mapping
Maps an interface to a primary VLAN
IC
4-193
Display Private VLAN Information
show vlan private-vlan
Shows private VLAN information
NE,
PE
4-194
Summary of Contents for 24/48 10/100 Ports + 2GE
Page 2: ......
Page 4: ...ES3526XA ES3552XA F2 2 6 3 E122006 CS R02 149100005500H...
Page 18: ...Contents xiv...
Page 22: ...Tables xviii...
Page 26: ...Figures xxii...
Page 34: ...Introduction 1 8 1...
Page 44: ...Initial Configuration 2 10 2...
Page 242: ...Configuring the Switch 3 198 3...
Page 498: ...Software Specifications A 4 A...
Page 511: ......
Page 512: ...ES3526XA ES3552XA E122006 CS R02D 149100005500H...