
BigIron RX Series Configuration Guide
315
53-1002253-01
Private VLANs
11
•
Isolated – Broadcasts and unknown unicasts received on isolated ports are sent only to
the primary port. They are not flooded to other ports in the isolated VLAN.
•
Community – Broadcasts and unknown unicasts received on community ports are sent to
the primary port and also are flooded to the other ports in the community VLAN.
Each private VLAN must have a primary VLAN. The primary VLAN is the interface between the
secured ports and the rest of the network. The private VLAN can have any combination of
community and isolated VLANs. (Refer to
“Configuration rules”
on page 316.)
Table 66
list the differences between private VLANs and standard VLANs.
Implementation notes
•
The private VLAN implementation in the current release uses the CPU for forwarding packets
on the primary VLAN’s “promiscuous” port. Other forwarding is performed in the hardware.
Support for the hardware forwarding in this feature sometimes results in multiple MAC address
entries for the same MAC address in the device’s MAC address table. In this case, each of the
entries is associated with a different VLAN. The multiple entries are a normal aspect of the
implementation of this feature and do not indicate a software problem.
•
By default, the primary VLAN does not forward broadcast or unknown unicast packets into the
private VLAN. You also can use MAC address filters to control traffic forwarded into and out of
the private VLAN. If you are implementing the private VLAN on a Layer 2 Switch, you also can
use ACLs to control the traffic into and out of the private VLAN.
Configuration notes
•
When Private VLAN mappings are enabled, the BigIron RX forwards unknown unicast, unknown
multicast, and broadcast packets in software. By default, the device forwards unknown
unicast, unknown multicast, and broadcast packets in hardware.
•
Release 02.4.00 supports private VLANs on untagged ports only. You cannot configure
isolated, community, or primary VLANs on 802.1Q tagged ports.
•
The device forwards all known unicast traffic in hardware. On the BigIron RX, multiple MAC
entries do not appear in the MAC address table because the device transparently manages
multiple MAC entries in hardware.
•
There is currently no support for IGMP Snooping within Private VLANs. In order to let clients in
Private VLANs get multicast traffic, IGMP Snooping must be disabled, so that all multicast
packets are treated as unregistered multicast packets and get flooded in software to all the
ports.
•
You can configure private VLANs and dual-mode VLAN ports on the same device. However, the
dual-mode VLAN ports cannot be members of Private VLANs.
TABLE 66
Comparison of private VLANs and standard port-based VLANs
Forwarding behavior
Private VLANs
Standard VLANs
All ports within a VLAN constitute a
common Layer broadcast domain
No
Yes
Broadcasts and unknown unicasts
are forwarded to all the VLAN’s ports
by default
No (isolated VLAN)
Yes (community VLAN)
Yes
Known unicasts
Yes
Yes
Summary of Contents for BigIron RX Series
Page 228: ...152 BigIron RX Series Configuration Guide 53 1002253 01 Enabling WAN PHY mode support 6 ...
Page 312: ...236 BigIron RX Series Configuration Guide 53 1002253 01 Displaying IP information 7 ...
Page 356: ...280 BigIron RX Series Configuration Guide 53 1002253 01 Resetting LLDP statistics 9 ...
Page 402: ...326 BigIron RX Series Configuration Guide 53 1002253 01 Transparent firewall mode 11 ...
Page 432: ...356 BigIron RX Series Configuration Guide 53 1002253 01 SuperSpan 12 ...
Page 500: ...424 BigIron RX Series Configuration Guide 53 1002253 01 MRP CLI example 14 ...
Page 591: ...BigIron RX Series Configuration Guide 515 53 1002253 01 Displaying traffic reduction 19 ...
Page 592: ...516 BigIron RX Series Configuration Guide 53 1002253 01 Displaying traffic reduction 19 ...
Page 598: ...522 BigIron RX Series Configuration Guide 53 1002253 01 Viewing Layer 2 ACLs 20 ...
Page 656: ...580 BigIron RX Series Configuration Guide 53 1002253 01 Trunk formation 22 ...
Page 754: ...678 BigIron RX Series Configuration Guide 53 1002253 01 Displaying RIP filters 24 ...
Page 814: ...738 BigIron RX Series Configuration Guide 53 1002253 01 Displaying OSPF information 25 ...
Page 980: ...904 BigIron RX Series Configuration Guide 53 1002253 01 Clearing IS IS information 28 ...
Page 1000: ...924 BigIron RX Series Configuration Guide 53 1002253 01 Using secure copy 30 ...
Page 1088: ...1012 BigIron RX Series Configuration Guide 53 1002253 01 IP source guard 35 ...
Page 1108: ...1032 BigIron RX Series Configuration Guide 53 1002253 01 Reading CDP packets 37 ...
Page 1126: ...1050 BigIron RX Series Configuration Guide 53 1002253 01 Clearing sFlow statistics 39 ...
Page 1324: ...1248 BigIron RX Series Configuration Guide 53 1002253 01 Displaying OSPFv3 information 48 ...
Page 1363: ...BigIron RX Series Configuration Guide 1287 53 1002253 01 Continuous System Monitor 51 ...
Page 1364: ...1288 BigIron RX Series Configuration Guide 53 1002253 01 Continuous System Monitor 51 ...
Page 1404: ...1328 BigIron RX Series Configuration Guide 53 1002253 01 Commands That Require a Reload D ...
Page 1458: ...1382 BigIron RX Series Configuration Guide 53 1002253 01 VSRP E ...