![Dell PowerConnect 8024 Скачать руководство пользователя страница 560](http://html.mh-extra.com/html/dell/powerconnect-8024/powerconnect-8024_user-configuration-manual_84530560.webp)
560
Configuring VLANs
Private VLANs
Private VLANs partition a standard VLAN domain into two or more
subdomains. Each subdomain is defined by a primary VLAN and a secondary
VLAN. The primary VLAN ID is the same for all subdomains that belong to a
particular private VLAN instance. The secondary VLAN ID differentiates the
subdomains from each other and provides layer 2 isolation between ports on
the same private VLAN.
The following types of VLANs can be configured in a private VLAN:
•
Primary VLAN
—Forwards the traffic from the promiscuous ports to
isolated ports, community ports and other promiscuous ports in the same
private VLAN. Only one primary VLAN can be configured per private
VLAN. All ports within a private VLAN share the same primary VLAN.
•
Isolated VLAN
—A secondary VLAN. It carries traffic from isolated ports
to promiscuous ports. Only one isolated VLAN can be configured per
private VLAN.
•
Community VLAN
—A secondary VLAN. It forwards traffic between ports
which belong to the same community and to the promiscuous ports. There
can be multiple community VLANs per private VLAN.
A port may be designated as one of the following types in a private VLAN:
•
Promiscuous port
—A port associated with a primary VLAN that is able to
communicate with all interfaces in the private VLAN, including other
promiscuous ports, community ports and isolated ports.
•
Host port
—A port associated with a secondary VLAN that can either
communicate with the promiscuous ports in the VLAN and with other
ports in the same community (if the secondary VLAN is a community
VLAN) or can communicate only with the promiscuous ports (if the
secondary VLAN is an isolated VLAN).
Private VLANs may be configured across a stack and on physical and port-
channel interfaces.
Private VLAN Usage Scenarios
Private VLANs are typically implemented in a DMZ for security reasons.
Servers in a DMZ are generally not allowed to communicate with each other
but they must communicate to a router, through which they are connected to
the users. Such servers are connected to host ports, and the routers are
Содержание PowerConnect 8024
Страница 48: ...48 Contents ...
Страница 52: ...52 Introduction ...
Страница 86: ...86 Switch Features ...
Страница 140: ...140 Setting Basic Network Information ...
Страница 178: ...178 Managing a Switch Stack ...
Страница 204: ...204 Configuring Authentication Authorization and Accounting ...
Страница 272: ...272 Managing General System Settings ...
Страница 308: ...308 Configuring SNMP ...
Страница 336: ...336 Managing Images and Files ...
Страница 354: ...354 Auto Image and Configuration Update ...
Страница 385: ...Monitoring Switch Traffic 385 Figure 16 26 Configure Additional Port Mirroring Settings 9 Click Apply ...
Страница 468: ...468 Configuring Port Characteristics ...
Страница 509: ...Configuring Port and System Security 509 Figure 20 12 Configure Port Security Settings 5 Click Apply ...
Страница 512: ...512 Configuring Port and System Security ...
Страница 550: ...550 Configuring Access Control Lists ...
Страница 571: ...Configuring VLANs 571 Figure 22 6 Add Ports to VLAN 4 Click Apply 5 Verify that the ports have been added to the VLAN ...
Страница 580: ...580 Configuring VLANs Figure 22 17 GVRP Port Parameters Table ...
Страница 586: ...586 Configuring VLANs Figure 22 24 Double VLAN Port Parameter Table ...
Страница 618: ...618 Configuring VLANs ...
Страница 631: ...Configuring the Spanning Tree Protocol 631 Figure 23 5 Spanning Tree Global Settings ...
Страница 637: ...Configuring the Spanning Tree Protocol 637 Figure 23 11 RSTP LAG Settings ...
Страница 685: ...Configuring Port Based Traffic Control 685 Figure 25 3 Storm Control 5 Click Apply ...
Страница 776: ...776 Snooping and Inspecting Traffic Figure 27 17 DAI Interface Configuration Summary ...
Страница 790: ...790 Snooping and Inspecting Traffic ...
Страница 797: ...Configuring Link Aggregation 797 To view or edit settings for multiple LAGs click Show All ...
Страница 894: ...894 Configuring DHCP Server Settings ...
Страница 928: ...928 Configuring L2 and L3 Relay Features Figure 34 3 DHCP Relay Interface Summary ...
Страница 955: ...Configuring OSPF and OSPFv3 955 Figure 35 1 OSPF Configuration ...
Страница 1030: ...1030 Configuring OSPF and OSPFv3 ...
Страница 1068: ...1068 Configuring VRRP ...
Страница 1092: ...1092 Configuring IPv6 Routing ...
Страница 1112: ...1112 Configuring DHCPv6 Server and Relay Settings Relay Interface Number Vl100 Relay Remote ID Option Flags ...
Страница 1119: ...Configuring Differentiated Services 1119 Figure 40 5 DiffServ Class Criteria ...
Страница 1126: ...1126 Configuring Differentiated Services Figure 40 14 DiffServ Service Summary ...
Страница 1142: ...1142 Configuring Differentiated Services ...
Страница 1148: ...1148 Configuring Class of Service Figure 41 1 Mapping Table Configuration CoS 802 1P ...
Страница 1160: ...1160 Configuring Class of Service ...
Страница 1164: ...1164 Configuring Auto VoIP Figure 42 2 Auto VoIP Interface Configuration ...
Страница 1230: ...1230 Managing IPv4 and IPv6 Multicast Figure 43 51 DVMRP Next Hop Summary ...
Страница 1256: ...1256 Managing IPv4 and IPv6 Multicast ...
Страница 1266: ...1266 Feature Limitations and Platform Constants ...
Страница 1274: ...1274 System Process Definitions ...
Страница 1294: ...Index 1294 ...