VLAN Configuration
3-209
3
Private VLANs
Private VLANs provide port-based security and isolation between ports within
the assigned VLAN. This switch supports private VLANs with primary/secondary
associated groups. A primary VLAN contains promiscuous ports that can
communicate with all other ports in the private VLAN group, while a secondary (or
community) VLAN contains community ports that can only communicate with other
hosts within the secondary VLAN and with any of the promiscuous ports in the
associated primary VLAN. In all cases, the promiscuous ports are designed to
provide open access to an external network such as the Internet, while the
community ports provide restricted access to local users.
Multiple primary VLANs can be configured on this switch, and multiple community
VLANs can be associated with each primary VLAN. (Note that private VLANs and
normal VLANs can exist simultaneously within the same switch.)
To configure primary/secondary associated groups, follow these steps:
1.
Use the Private VLAN Configuration menu (page 3-210) to designate one or
more community VLANs, and the primary VLAN that will channel traffic outside
of the VLAN groups.
2.
Use the Private VLAN Association menu (page 3-211) to map the secondary
(i.e., community) VLAN(s) to the primary VLAN.
3.
Use the Private VLAN Port Configuration menu (page 3-213) to set the port
type to promiscuous (i.e., having access to all ports in the primary VLAN), or
host (i.e., having access restricted to community VLAN members, and
channeling all other traffic through promiscuous ports). Then assign any
promiscuous ports to a primary VLAN and any host ports a community VLAN.
Displaying Current Private VLANs
The Private VLAN Information page displays information on the private VLANs
configured on the switch, including primary, community, and isolated VLANs, and
their assigned interfaces.
Command Attributes
•
VLAN ID
– ID of configured VLAN (1-4092), and VLAN type.
•
Primary VLAN
– The VLAN with which the selected VLAN ID is associated. A
primary VLAN displays its own ID, a community VLAN displays the associated
primary VLAN, and an isolated VLAN displays the stand-alone VLAN.
•
Ports List
– The list of ports (and assigned port type) in the selected private VLAN.
Содержание iES4028F
Страница 1: ...iES4028F 4028FP 4024GP ...
Страница 2: ...iES4028F iES4028FP iES4024GP E082008 ST R03 149100041800A 149100040200A 149100041700A 149100000020A ...
Страница 4: ...iv This page is intentionally left blank ...
Страница 10: ...x This page is intentionally left blank ...
Страница 28: ...Contents xxviii This page is intentionally left blank ...
Страница 32: ...Tables xxxii This page is intentionally left blank ...
Страница 46: ...Introduction 1 10 1 This page is intentionally left blank ...
Страница 336: ...Configuring the Switch 3 280 3 This page is intentionally left blank ...
Страница 688: ...Command Line Interface 4 352 4 This page is intentionally left blank ...
Страница 702: ...Glossary Glossary 8 This page is intentionally left blank ...
Страница 710: ...Index 8 Index This page is intentionally left blank ...
Страница 711: ...This page is intentionally left blank ...
Страница 712: ...iES4028F 4028FP 4024GP ...