
318
BigIron RX Series Configuration Guide
53-1002253-01
Private VLANs
11
Enabling broadcast, multicast or unknown unicast traffic to the private
VLAN
To enhance private VLAN security, the primary private VLAN does not forward broadcast or
unknown unicast packets to its community and isolated VLANs. For example, if port 3/2 in
Figure 30
on page 314 receives a broadcast packet from the firewall, the port does not forward the
packet to the other private VLAN ports (3/5, 3/6, 3/9, and 3/10).
This forwarding restriction does not apply to traffic from the private VLAN. The primary port does
forward broadcast and unknown unicast packets that are received from the isolated and
community VLANs. For example, if the host on port 3/9 sends an unknown unicast packet, port 3/2
forwards the packet to the firewall.
If you want to remove the forwarding restriction, you can enable the primary port to forward
broadcast or unknown unicast traffic, if desired, using the following CLI method. You can enable or
disable forwarding of broadcast or unknown unicast packets separately.
Using the CLI
To configure the ports in the primary VLAN to forward broadcast, multicast or unknown unicast
traffic received from sources outside the private VLAN, enter the following commands at the global
CONFIG level of the CLI.
BigIron RX(config)# pvlan-preference broadcast flood
BigIron RX(config)# pvlan-preference unknown-unicast flood
These commands enable forwarding of broadcast, multicast and unknown-unicast packets to ports
within the private VLAN. To again disable forwarding, enter a command such as the following.
BigIron RX(config)# no pvlan-preference broadcast flood
This command disables forwarding of broadcast packets within the private VLAN.
Syntax: [no] pvlan-preference broadcast | unknown-unicast flood
CLI example for
Figure 30
To configure the private VLANs shown in
Figure 30
on page 314, enter the following commands.
BigIron RX(config)# vlan 901
BigIron RX(config-vlan-901)# untagged ethernet 3/5 to 3/6
BigIron RX(config-vlan-901)# pvlan type community
BigIron RX(config-vlan-901)# exit
BigIron RX(config)# vlan 902
BigIron RX(config-vlan-902)# untagged ethernet 3/9 to 3/10
BigIron RX(config-vlan-902)# pvlan type isolated
BigIron RX(config-vlan-902)# exit
BigIron RX(config)# vlan 903
BigIron RX(config-vlan-903)# untagged ethernet 3/5 to 3/6
BigIron RX(config-vlan-903)# pvlan type community
BigIron RX(config-vlan-903)# exit
BigIron RX(config)# vlan 7
BigIron RX(config-vlan-7)# untagged ethernet 3/2
BigIron RX(config-vlan-7)# pvlan type primary
BigIron RX(config-vlan-7)# pvlan mapping 901 ethernet 3/2
BigIron RX(config-vlan-7)# pvlan mapping 902 ethernet 3/2
BigIron RX(config-vlan-7)# pvlan mapping 903 ethernet 3/2
Summary of Contents for BigIron RX Series
Page 228: ...152 BigIron RX Series Configuration Guide 53 1002253 01 Enabling WAN PHY mode support 6 ...
Page 312: ...236 BigIron RX Series Configuration Guide 53 1002253 01 Displaying IP information 7 ...
Page 356: ...280 BigIron RX Series Configuration Guide 53 1002253 01 Resetting LLDP statistics 9 ...
Page 402: ...326 BigIron RX Series Configuration Guide 53 1002253 01 Transparent firewall mode 11 ...
Page 432: ...356 BigIron RX Series Configuration Guide 53 1002253 01 SuperSpan 12 ...
Page 500: ...424 BigIron RX Series Configuration Guide 53 1002253 01 MRP CLI example 14 ...
Page 591: ...BigIron RX Series Configuration Guide 515 53 1002253 01 Displaying traffic reduction 19 ...
Page 592: ...516 BigIron RX Series Configuration Guide 53 1002253 01 Displaying traffic reduction 19 ...
Page 598: ...522 BigIron RX Series Configuration Guide 53 1002253 01 Viewing Layer 2 ACLs 20 ...
Page 656: ...580 BigIron RX Series Configuration Guide 53 1002253 01 Trunk formation 22 ...
Page 754: ...678 BigIron RX Series Configuration Guide 53 1002253 01 Displaying RIP filters 24 ...
Page 814: ...738 BigIron RX Series Configuration Guide 53 1002253 01 Displaying OSPF information 25 ...
Page 980: ...904 BigIron RX Series Configuration Guide 53 1002253 01 Clearing IS IS information 28 ...
Page 1000: ...924 BigIron RX Series Configuration Guide 53 1002253 01 Using secure copy 30 ...
Page 1088: ...1012 BigIron RX Series Configuration Guide 53 1002253 01 IP source guard 35 ...
Page 1108: ...1032 BigIron RX Series Configuration Guide 53 1002253 01 Reading CDP packets 37 ...
Page 1126: ...1050 BigIron RX Series Configuration Guide 53 1002253 01 Clearing sFlow statistics 39 ...
Page 1324: ...1248 BigIron RX Series Configuration Guide 53 1002253 01 Displaying OSPFv3 information 48 ...
Page 1363: ...BigIron RX Series Configuration Guide 1287 53 1002253 01 Continuous System Monitor 51 ...
Page 1364: ...1288 BigIron RX Series Configuration Guide 53 1002253 01 Continuous System Monitor 51 ...
Page 1404: ...1328 BigIron RX Series Configuration Guide 53 1002253 01 Commands That Require a Reload D ...
Page 1458: ...1382 BigIron RX Series Configuration Guide 53 1002253 01 VSRP E ...