C
ONFIGURING
THE
S
WITCH
3-176
Configuring Private VLANs
Private VLANs provide port-based security between ports within the
assigned VLAN. This switch supports primary/secondary associated
groups of private VLAN. A primary VLAN contains promiscuous ports
that can communicate with all other ports in the private VLAN group,
while a secondary (or community) VLAN contains community ports that
can only communicate with other hosts within the secondary VLAN and
with any of the promiscuous ports in the associated primary VLAN. In
both cases, the promiscuous ports are designed to provide open access to
an external network such as the Internet, while the community ports
provide restricted access to local users.
Multiple primary VLANs can be configured on this switch, and multiple
community VLANs can be associated with each primary VLAN. (Note
that private VLANs and normal VLANs can exist simultaneously within
the same switch.)
To configure primary/secondary associated groups, follow these steps:
1. Use the Private VLAN Configuration menu to designate one or more
community VLANs, and the primary VLAN that will channel traffic
outside of the VLAN groups.
2. Use the Private VLAN Association menu to map the secondary (i.e.,
community) VLAN(s) to the primary VLAN.
3. Use the Private VLAN Port Configuration menu to set the port type to
promiscuous (i.e., having access to all ports in the primary VLAN), or
host (i.e., having access restricted to community VLAN members, and
channeling all other traffic through promiscuous ports). Then assign
any promiscuous ports to a primary VLAN and any host ports a
community VLAN.
Summary of Contents for 6128L2
Page 2: ......
Page 21: ...CONTENTS xvii Glossary Index ...
Page 22: ...CONTENTS xviii ...
Page 26: ...TABLES xxii ...
Page 40: ...INTRODUCTION 1 10 ...
Page 54: ...INITIAL CONFIGURATION 2 14 ...
Page 193: ...PORT CONFIGURATION 3 139 Figure 3 61 Displaying Etherlike and RMON Statistics ...
Page 257: ...QUALITY OF SERVICE 3 203 Figure 3 90 Configuring Policy Maps ...
Page 313: ...COMMAND GROUPS 4 13 PE Privileged Exec VC VLAN Database Configuration ...
Page 592: ...TROUBLESHOOTING B 4 ...
Page 605: ......