Configuration Guide
Private VLAN Configuration
Private VLAN Configuration
Private VLAN Technology
If the service provider offers a VLAN to each subscriber, the service provider
supports a limited number of subscribers because one device supports 4096
VLANs at most. On the layer 3 device, each VLAN is assigned with a subnet
address or a series of addresses, which results in a waste of IP addresses. In
this case, private VLAN comes into being.
A private VLAN divides the layer 2 broadcast domain of a VLAN into several sub
domains. Each sub domain consists of a private VLAN pair: primary VLAN and
secondary VLAN.
A private VLAN domain can have multiple private VLAN pairs, and each VLAN
pair represents a sub domain. All the private VLAN pairs in one private VLAN
domain share a primary VLAN. Each sub domain has a different secondary
VLAN IDs.
There is only one primary VLAN in each private VLAN domain. The secondary
VLAN is used for layer 2 separation in the same private VLAN domain. There
are two types of secondary VLANs:
Isolated VLAN: Layer 2 communication is not possible for the ports in the
same isolated VLAN. There is only one isolated VLAN in a private VLAN
domain.
Community VLAN: The ports in the same community VLAN can perform
layer 2 communication, but not with the ports in other community VLANs.
There can be multiple community VLANs in a private VLAN domains.
Promiscuous port, a port in the primary VLAN, can communicate with any port,
including the isolated port and community port of the secondary VLAN in the
same private VLAN.
Isolated port, a port in the isolated VLAN, can only communicate with the
promiscuous port. The packets received on the isolated port are allowed to be
forwarded to the Trunk Port, but the packets in the isolated VLAN received on
the Trunk Port cannot be forwarded to the isolated port.
Isolated Trunk Port, can be the member port of multiple ordinary VLANs and
PVLANs. In the isolated VLAN, the isolated trunk port can only communicate
with the promiscuous port; in the community VLAN, it can communicate with the
community ports in the same community VLAN and the promiscuous port; in the
ordinary VLAN, it follows the 802.1Q rule. The packets in the isolated VLAN
received on the isolated trunk port are allowed to be forwarded to the Trunk Port,
Summary of Contents for RG-S2900G-E Series
Page 1: ...RG S2900G E Series Switch RGOS Configuration Guide Release 10 4 2b12 p1 ...
Page 91: ...Configuration Guide Configuring PoE Configuration ...
Page 133: ...Configuration Guide EEE Configuration ...
Page 319: ...Configuration Guide QinQ Configuration ...
Page 408: ......
Page 409: ...IP Routing Configuration 1 Static Route Configuration ...
Page 412: ......
Page 413: ...Multicast Configuration 1 IGMP Snooping Configuration 2 MLD Snooping Configuration ...
Page 757: ......
Page 758: ...ACL QoS Configuration 1 Access Control List Configuration 2 QoS Configuration ...
Page 801: ...Reliability Configuration 1 RLDP Configuration 2 TPP Configuration 3 SEM Configuration ...
Page 901: ...Configuration Guide ERSPAN Configuration ...
Page 902: ...Web based Configuration 1 Web based Configuration ...