
C H A P T E R
14-1
Cisco Nexus 1000V Troubleshooting Guide, Release 5.2(1)SV3(1.1)
OL-31593-01
14
Private VLANs
This chapter describes how to identify and resolve problems related to private VLANs and includes the
following sections:
•
Information About Private VLANs, page 14-1
•
Troubleshooting Guidelines, page 14-2
•
Private VLAN Troubleshooting Commands, page 14-2
Information About Private VLANs
Private VLANs (PVLANs) are used to segregate Layer 2 Internet service provider (ISP) traffic and
convey it to a single router interface. PVLANs achieve device isolation by applying Layer 2 forwarding
constraints that allow end devices to share the same IP subnet while being Layer 2 isolated. The use of
larger subnets reduces address management overhead. Three separate port designations are used. Each
has its own unique set of rules that regulate each connected endpoint's ability to communicate with other
connected endpoints within the same private VLAN domain.
Private VLAN Domains
A private VLAN domain consists of one or more pairs of VLANs. The primary VLAN makes up the
domain, and each VLAN pair makes up a subdomain. The VLANs in a pair are called the primary VLAN
and the secondary VLAN. All VLAN pairs within a private VLAN have the same primary VLAN. The
secondary VLAN ID is what differentiates one subdomain from another.
Spanning Multiple Switches
Private VLANs can span multiple switches, just like regular VLANs. Inter-switch link ports do not need
to be aware of the special VLAN type and can carry frames tagged with these VLANs as like they do
with any other frames. Private VLANs ensure that traffic from an isolated port in one switch does not
reach another isolated or community port in a different switch even after traversing an inter-switch link.
By embedding the isolation information at the VLAN level and by transporting it along with the packet,
you can maintain consistent behavior throughout the network. The mechanism that restricts Layer 2
communication between two isolated ports in the same switch also restricts Layer 2 communication
between two isolated ports in two different switches.
Содержание Nexus 1000V
Страница 12: ...Contents xii Cisco Nexus 1000V Troubleshooting Guide Release 5 2 1 SV3 1 1 OL 31593 01 ...
Страница 16: ...xvi Cisco Nexus 1000V Troubleshooting Guide Release 5 2 1 SV3 1 1 OL 31593 01 New and Changed Information ...
Страница 112: ...8 2 Cisco Nexus 1000V Troubleshooting Guide Release 5 2 1 SV3 1 1 OL 31593 01 Chapter 8 L3Sec Troubleshooting L3Sec ...
Страница 170: ...13 4 Cisco Nexus 1000V Troubleshooting Guide Release 5 2 1 SV3 1 1 OL 31593 01 Chapter 13 VLANs Cannot Create a VLAN ...
Страница 232: ...22 14 Cisco Nexus 1000V Troubleshooting Guide Release 5 2 1 SV3 1 1 OL 31593 01 Chapter 22 System Error Messages ...