![Dell PowerConnect M6220 Скачать руководство пользователя страница 571](http://html.mh-extra.com/html/dell/powerconnect-m6220/powerconnect-m6220_user-configuration-manual_84547571.webp)
Configuring VLANs
571
•
Isolated VLAN
—A secondary VLAN. It carries traffic from isolated ports
to promiscuous ports. Only one isolated VLAN can be configured per
private VLAN.
•
Community VLAN
—A secondary VLAN. It forwards traffic between ports
which belong to the same community and to the promiscuous ports. There
can be multiple community VLANs per private VLAN.
A port may be designated as one of the following types in a private VLAN:
•
Promiscuous port
—A port associated with a primary VLAN that is able to
communicate with all interfaces in the private VLAN, including other
promiscuous ports, community ports and isolated ports.
•
Host port
—A port associated with a secondary VLAN that can either
communicate with the promiscuous ports in the VLAN and with other
ports in the same community (if the secondary VLAN is a community
VLAN) or can communicate only with the promiscuous ports (if the
secondary VLAN is an isolated VLAN).
Private VLANs may be configured across a stack and on physical and port-
channel interfaces.
Private VLAN Usage Scenarios
Private VLANs are typically implemented in a DMZ for security reasons.
Servers in a DMZ are generally not allowed to communicate with each other
but they must communicate to a router, through which they are connected to
the users. Such servers are connected to host ports, and the routers are
attached to promiscuous ports. Then, if one of the servers is compromised,
the intruder cannot use it to attack another server in the same network
segment.
The same traffic isolation can be achieved by assigning each port with a
different VLAN, allocating an IP subnet for each VLAN, and enabling layer 3
routing between them. In a private VLAN domain, on the other hand, all
members can share the common address space of a single subnet, which is
associated with a primary VLAN. So, the advantage of the private VLANs
feature is that it reduces the number of consumed VLANs, improves IP
addressing space utilization, and helps to avoid layer 3 routing.
Содержание PowerConnect M6220
Страница 52: ...52 Introduction ...
Страница 86: ...86 Switch Features ...
Страница 100: ...100 Hardware Overview ...
Страница 116: ...116 Using the Command Line Interface ...
Страница 121: ...Default Settings 121 ...
Страница 122: ...122 Default Settings ...
Страница 142: ...142 Setting Basic Network Information ...
Страница 206: ...206 Configuring Authentication Authorization and Accounting ...
Страница 292: ...292 Managing General System Settings Figure 11 31 Verify MOTD ...
Страница 296: ...296 Managing General System Settings ...
Страница 332: ...332 Configuring SNMP ...
Страница 408: ...408 Monitoring Switch Traffic ...
Страница 560: ...560 Configuring Access Control Lists ...
Страница 582: ...582 Configuring VLANs Figure 21 6 Add Ports to VLAN 4 Click Apply 5 Verify that the ports have been added to the VLAN ...
Страница 591: ...Configuring VLANs 591 Figure 21 17 GVRP Port Parameters Table ...
Страница 597: ...Configuring VLANs 597 Figure 21 24 Double VLAN Port Parameter Table ...
Страница 693: ...Configuring Port Based Traffic Control 693 Figure 24 3 Storm Control 5 Click Apply ...
Страница 780: ...780 Configuring Connectivity Fault Management ...
Страница 804: ...804 Snooping and Inspecting Traffic Figure 27 17 DAI Interface Configuration Summary ...
Страница 818: ...818 Snooping and Inspecting Traffic ...
Страница 836: ...836 Configuring Link Aggregation ...
Страница 860: ...860 Configuring Data Center Bridging Features ...
Страница 906: ...906 Configuring DHCP Server Settings ...
Страница 940: ...940 Configuring L2 and L3 Relay Features Figure 34 3 DHCP Relay Interface Summary ...
Страница 1080: ...1080 Configuring VRRP ...
Страница 1104: ...1104 Configuring IPv6 Routing ...
Страница 1124: ...1124 Configuring DHCPv6 Server and Relay Settings Relay Interface Number Vl100 Relay Remote ID Option Flags ...
Страница 1131: ...Configuring Differentiated Services 1131 Figure 40 5 DiffServ Class Criteria ...
Страница 1158: ...1158 Configuring Class of Service Figure 41 1 Mapping Table Configuration CoS 802 1P ...
Страница 1174: ...1174 Configuring Auto VoIP Figure 42 2 Auto VoIP Interface Configuration ...
Страница 1240: ...1240 Managing IPv4 and IPv6 Multicast Figure 43 51 DVMRP Next Hop Summary ...
Страница 1266: ...1266 Managing IPv4 and IPv6 Multicast ...
Страница 1274: ...1274 System Process Definitions ...
Страница 1294: ...1294 Index ...