Chapter 18
| VLAN Commands
Configuring VLAN Interfaces
– 447 –
Syntax
[
no
]
switchport ingress-filtering
Default Setting
Enabled
Command Mode
Interface Configuration (Ethernet, Port Channel)
Command Usage
◆
Ingress filtering only affects tagged frames.
◆
If ingress filtering is disabled and a port receives frames tagged for VLANs
for which it is not a member, these frames will be flooded to all other ports
(except for those VLANs explicitly forbidden on this port).
◆
If ingress filtering is enabled and a port receives frames tagged for VLANs
for which it is not a member, these frames will be discarded.
◆
Ingress filtering does not affect VLAN independent BPDU frames, such as
GVRP or STA. However, they do affect VLAN dependent BPDU frames,
such as GMRP.
Example
The following example shows how to set the interface to port 1 and then
enable ingress filtering:
Console(config)#interface ethernet 1/1
Console(config-if)#switchport ingress-filtering
Console(config-if)#
switchport mode
This command configures the VLAN membership mode for a port. Use the
no
form to restore the default.
Syntax
switchport mode
{
access
|
hybrid
|
trunk
}
no switchport mode
access
- Specifies an access VLAN interface. The port transmits and
receives untagged frames on a single VLAN only.
hybrid
- Specifies a hybrid VLAN interface. The port may transmit
tagged or untagged frames.
trunk
- Specifies a port as an end-point for a VLAN trunk. A trunk is
a direct link between two switches, so the port transmits tagged
frames that identify the source VLAN. Note that frames belonging to
the port’s default VLAN (i.e., associated with the PVID) are also
transmitted as tagged frames.