
10-20
Catalyst 4500 Series, Catalyst 2948G, Catalyst 2948G-GE-TX, and Catalyst 2980G Switches Software Configuration Guide—Release 8.2GLX
78-15908-01
Chapter 10 Configuring VLANs
Configuring Private VLANs
To create a private VLAN, perform this task in privileged mode:
This example shows how to create a private VLAN using VLAN 7 as the primary VLAN, VLAN 901 as
the isolated VLAN, and VLANs 902 and 903 as the community VLANs. VLAN 901 uses module 4,
port 3. VLAN 902 uses module 4, ports 4 through 6. VLAN 903 uses module 4, ports 7 through 9. The
router is attached to the promiscuous port 3/1.
Before starting, verify that VLANs 7, 901, 902, and 903 have no ports that are assigned to them by using
the show vlan vlan_num command. If any ports are assigned to one or more of these VLANs, set them
to some other VLAN using the set vlan vlan_num {mod/port} command.
This example shows how to specify VLAN 7 as the primary VLAN:
Console> (enable) set vlan 7 pvlan-type primary
Vlan 7 configuration successful
Console> (enable)
This example shows how to specify VLAN 901 as the isolated VLAN and VLANs 902 and 903 as the
community VLANs:
Console> (enable) set vlan 901 pvlan-type isolated
Vlan 901 configuration successful
Console> (enable) set vlan 902 pvlan-type community
Vlan 902 configuration successful
Console> (enable) set vlan 903 pvlan-type community
Vlan 903 configuration successful
Console> (enable)
This example shows how to bind VLAN 901 to primary VLAN 7 and assign port 4/3 as the isolated port:
Console> (enable) set pvlan 7 901 4/3
Successfully set the following ports to Private Vlan 7,901: 4/3
Console> (enable)
This example shows how to bind VLAN 902 to primary VLAN 7 and assign ports 4/4 through 4/6 as the
community port:
Console> (enable) set pvlan 7 902 4/4-6
Successfully set the following ports to Private Vlan 7,902:4/4-6
Console> (enable)
Task
Command
Step 1
Create the primary VLAN.
set vlan vlan_num pvlan-type primary
Step 2
Set the isolated or community VLAN(s).
set vlan vlan_num pvlan-type {isolated |
community}
Step 3
Bind the isolated or community VLAN(s) to the
primary VLAN and associate the isolated or
community port(s) to the private VLAN.
set pvlan primary_vlan_num {isolated_vlan_num |
community_vlan_num}mod/ports
Step 4
Map the isolated/community VLAN to the
primary VLAN on the promiscuous port.
set pvlan mapping primary_vlan_num
{isolated_vlan_num | community_vlan_num}
mod/ports
Step 5
Verify the private VLAN configuration.
show pvlan [vlan_num]
show pvlan mapping