47-6
Catalyst 4500 Series Switch, Cisco IOS Software Configuration Guide - Cisco IOS XE 3.9.xE and IOS 15.2(5)Ex
Chapter 47 Configuring Private VLANs
About Private VLANs
Because VTP does not support PVLANs, you must manually configure PVLANs on all switches in the
Layer 2 network. If you do not configure the primary and secondary VLAN association in some switches
in the network, the Layer 2 databases in these switches are not merged. This can result in unnecessary
flooding of private-VLAN traffic on those switches.
Note
PVLANs are supported in VTP v3 under server mode.
Isolated PVLAN Trunk Ports
You would use a isolated PVLAN trunk ports when you would anticipate using PVLAN isolated host
ports to carry multiple VLANs, either normal VLANs or for multiple PVLAN domains. This makes it
useful for connecting a downstream switch that does not support PVLANs such as Catalyst 2950.
Figure 47-3
Isolated PVLAN Trunk Ports
In this illustration, a Catalyst 4500 switch is being used to connect a downstream switch that does not
support PVLANs.
Traffic being sent in the downstream direction towards host1 from the router is received by the
Catalyst 4500 series switch on the promiscuous port and in the primary VLAN (VLAN 10). The packets
are then switched out of the isolated PVLAN trunk. Rather that being tagged with the primary VLAN
(VLAN 10), they are transmitted with the isolated VLAN’s tag (VLAN 11). In this way, when the packets
arrive on the non-PVLAN switch, they can be bridged to the destination hosts’ access port.
C
a
t
a
ly
s
t 7200
ro
u
ter
C
a
t
a
ly
s
t
4500
s
witch
Non-PVLAN
s
witch (2950)
Prim
a
ry VLAN
= VLAN10
I
s
ol
a
ted VLAN
= VLAN11
I
s
ol
a
ted PVLAN
tr
u
nk port
Acce
ss
port
s
on VLAN11
I
s
ol
a
ted port
204202
Summary of Contents for Catalyst 4500 Series
Page 2: ......
Page 4: ......
Page 2086: ...Index IN 46 Software Configuration Guide Release IOS XE 3 9 0E and IOS 15 2 5 E ...