P
RIVATE
VLAN C
OMMANDS
3-133
Command Mode
VLAN Configuration
Command Usage
• Private VLANs are used to restrict traffic to ports within the same
VLAN “community,” and channel traffic passing outside the
community through promiscuous ports that have been mapped to the
associated “primary” VLAN.
• Port membership for private VLANs is static. Once a port has been
assigned to a private VLAN, it cannot be dynamically moved to
another VLAN via GVRP.
• Private VLAN ports cannot be set to trunked mode. (See “switchport
mode” on page 3-125.)
Example
private-vlan association
Use this command to associate a primary VLAN with a secondary (i.e.,
community) VLAN. Use the
no
form to remove all associations for the
specified primary VLAN.
Syntax
private-vlan
primary-vlan-id
association
{
secondary-vlan-id
|
add
secondary-vlan-id
|
remove
secondary-vlan-id
}
no private-vlan
primary-vlan-id
association
•
primary-vlan-id
- ID of private VLAN. (Range: 1-4094, no leading
zeroes).
•
secondary-vlan-id
- ID of private (ie. isolated or community) VLAN.
(Range: 1-4094, no leading zeroes).
Default Setting
None
Console(config)#vlan database
Console(config-vlan)#private-vlan 2 primary
Console(config-vlan)#private-vlan 3 community
Console(config)#
Summary of Contents for 6724AL2
Page 2: ......
Page 404: ...COMMAND LINE INTERFACE 3 216 ...
Page 406: ...TROUBLESHOOTING A 2 ...
Page 418: ...GLOSSARY Glossary 8 ...
Page 422: ...INDEX Index 4 ...
Page 423: ......