User’s Manual of IGSW-2840
571
To configure isolated VLANs, follow these steps:
1. Use the
private-vlan
command to designate an isolated VLAN that will contain a single promiscuous port and one or more
isolated ports.
2. Use the
switchport mode private-vlan
command to configure one port as promiscuous (i.e., having access to all ports in
the isolated VLAN) one or more ports as host (i.e., isolated port).
3. Use the switchport private-vlan isolated command to assign a port to an isolated VLAN.
4. Use the show private-vlan command to verify your configuration settings.
private-vlan
Use this command to create a primary, community, or isolated private VLAN. Use the no form to remove the specified private
VLAN.
Syntax
private-vlan vlan-id {community | primary | isolated}
no private-vlan vlan-id vlan-id -ID of private VLAN.
•
(Range: 1-4094, no leading zeroes).
•
community - A VLAN in which traffic is restricted to host members in the same VLAN and to promiscuous ports in the
associate primary VLAN.
•
primary - A VLAN which can contain one or more community VLANs, and serves to channel traffic between community
VLANs and other locations.
•
isolated – Specifies an isolated VLAN. Ports assigned to an isolated VLAN can only communicate with the promiscuous
port within their own VLAN.
Default Setting
None
Command Mode
VLAN Configuration
Command Usage
•
Private VLANs are used to restrict traffic to ports within the same community or isolated VLAN, and channel traffic
passing outside the community through promiscuous ports. When using community VLANs, they must be mapped to
an associated “primary” VLAN that contains promiscuous ports. When using an isolated VLAN, it must be configured to
contain a single promiscuous port.
•
Port membership for private VLANs is static. Once a port has been assigned to a private VLAN, it cannot be
dynamically moved to another VLAN via GVRP.
•
Private VLAN ports cannot be set to trunked mode. (See “switchport mode” on page 4-228.)
Example
Console(config)#vlan database
Console(config-vlan)#private-vlan 2 primary
Console(config-vlan)#private-vlan 3 community
Console(config)#
Summary of Contents for IGSW-2840
Page 23: ...User s Manual of IGSW 2840 23 A 2 10 100Mbps 10 100Base TX 665 APPENDEX B GLOSSARY 667 ...
Page 110: ...User s Manual of IGSW 2840 110 Figure 4 3 14 SNMPv3 View Edit screenshot ...
Page 119: ...User s Manual of IGSW 2840 119 Figure 4 4 7 Mirror Port Configuration screenshot ...
Page 205: ...User s Manual of IGSW 2840 205 Multicast Service Multicast flooding ...
Page 216: ...User s Manual of IGSW 2840 216 Figure 4 9 7 IGMP Member Port Table screenshot ...
Page 280: ...User s Manual of IGSW 2840 280 Figure 4 11 19 SSH Host Key Settings screenshot ...
Page 315: ...User s Manual of IGSW 2840 315 Figure 4 11 44 MAC ACL Settings screenshot ...
Page 317: ...User s Manual of IGSW 2840 317 Figure 4 11 46 ACL Port Binding Settings screenshot ...
Page 431: ...User s Manual of IGSW 2840 431 tacacs 1 Console ...