•
You can change the association between a secondary and primary VLAN by removing the existing
association, and then adding the desired association.
If you delete either the primary or secondary VLAN, the VLAN becomes inactive on the port where the
association is configured. When you enter the
no private-vlan
command, the VLAN returns to the normal
VLAN mode. All primary and secondary associations on that VLAN are suspended, but the interfaces remain
in PVLAN mode. If you convert the specified VLAN to PVLAN mode again, the original associations are
reinstated.
If you enter the
no vlan
command for the primary VLAN, all the PVLAN associations with that VLAN are
lost. However, if you enter the
no vlan
command for a secondary VLAN, the PVLAN associations with that
VLAN are suspended and are reinstated when you recreate the specified VLAN and configure it as the previous
secondary VLAN.
Before You Begin
Ensure that the PVLAN feature is enabled.
Procedure
Purpose
Command or Action
Enters global configuration mode.
switch#
configure terminal
Step 1
Enters the number of the primary VLAN that you are
working in for the PVLAN configuration.
switch(config)#
vlan primary-vlan-id
Step 2
Associates the secondary VLANs with the primary
VLAN. Use the
remove
keyword with a
switch(config-vlan)#
private-vlan
association
{[
add
]
secondary-vlan-list
|
remove secondary-vlan-list
}
Step 3
secondary-vlan-list
to clear the association between
secondary VLANs and a primary VLAN.
(Optional)
Removes all associations from the primary VLAN and
returns it to normal VLAN mode.
switch(config-vlan)#
no private-vlan
association
Step 4
The following example shows how to associate community VLANs 100 through 110 and isolated VLAN 200
with primary VLAN 5:
switch#
configure terminal
switch(config)#
vlan 5
switch(config-vlan)#
private-vlan association 100-110, 200
Private VLAN Ports
The following are three types of PVLAN ports:
•
Promiscuous port
—
A promiscuous port belongs to a primary VLAN. The promiscuous port can
communicate with all interfaces, including the community and isolated host ports, that belong to those
secondary VLANs associated to the promiscuous port and associated with the primary VLAN. You can
have several promiscuous ports in a primary VLAN. Each promiscuous port can have several secondary
VLANs or no secondary VLANs that are associated to that port. You can associate a secondary VLAN
Cisco Nexus 6000 Series NX-OS Layer 2 Switching Configuration Guide, Release 7.x
30
Configuring Private VLANs
Private VLAN Ports