◦
Configure the
private-vlan type
as primary, configure the same
private-vlan association
under
that VLAN, and then remove the association using the
no private-vlan association
command.
Information About Private VLANs
A private VLAN (PVLAN) partitions the Ethernet broadcast domain of a VLAN into subdomains, allowing
you to isolate the ports on the switch from each other. A subdomain consists of a primary VLAN and one or
more secondary VLANs (see the following figure). All VLANs in a PVLAN domain share the same primary
VLAN. The secondary VLAN ID differentiates one subdomain from another. The secondary VLAN can either
be isolated VLAN or community VLAN. A host on an isolated VLAN can communicate only with the
associated promiscuous port in its primary VLAN. Hosts on community VLAN can communicate among
themselves and with their associated promiscuous port but not with ports in other community VLANs.
Figure 4: Private VLAN Domain
You must first create the VLAN before converting it to a PVLAN, either a primary VLAN or secondary
VLAN.
Note
Primary and Secondary VLANs in Private VLANs
A private VLAN domain has only one primary VLAN. Each port in a private VLAN domain is a member of
the primary VLAN; the primary VLAN is the entire private VLAN domain.
Cisco Nexus 6000 Series NX-OS Layer 2 Switching Configuration Guide, Release 7.x
28
Configuring Private VLANs
Information About Private VLANs