VLAN Configuration
3-181
3
CLI
– This example sets port 1 to tunnel access mode, indicates that the TPID used
for 802.1Q tagged frames is 9100 hexadecimal, and sets port 2 to tunnel uplink
mode.
Private VLANs
Private VLANs provide port-based security and isolation between ports within
the assigned VLAN. This switch supports two types of private VLANs: primary/
secondary associated groups, and stand-alone isolated VLANs. A primary VLAN
contains promiscuous ports that can communicate with all other ports in the private
VLAN group, while a secondary (or community) VLAN contains community ports
that can only communicate with other hosts within the secondary VLAN and with any
of the promiscuous ports in the associated primary VLAN. Isolated VLANs, on the
other hand, consist a single stand-alone VLAN that contains one promiscuous port
and one or more isolated (or host) ports. In all cases, the promiscuous ports are
designed to provide open access to an external network such as the Internet, while
the community or isolated ports provide restricted access to local users.
Multiple primary VLANs can be configured on this switch, and multiple community
VLANs can be associated with each primary VLAN. One or more isolated VLANs
can also be configured. (Note that private VLANs and normal VLANs can exist
simultaneously within the same switch.)
To configure primary/secondary associated groups, follow these steps:
1.
Use the Private VLAN Configuration menu (page 3-183) to designate one or
more community VLANs, and the primary VLAN that will channel traffic outside
of the VLAN groups.
2.
Use the Private VLAN Association menu (page 3-184) to map the secondary
(i.e., community) VLAN(s) to the primary VLAN.
Console(config)#interface ethernet 1/1
4-166
Console(config-if)#switchport dot1q-tunnel mode access
4-234
Console(config-if)#switchport dot1q-tunnel tpid 9100
4-235
Console(config-if)#interface ethernet 1/2
Console(config-if)#switchport dot1q-tunnel mode uplink
4-234
Console(config-if)#end
Console#show dot1q-tunnel
4-236
Current double-tagged status of the system is Enabled
The dot1q-tunnel mode of the set interface 1/1 is Access mode, TPID is 0x9100.
The dot1q-tunnel mode of the set interface 1/2 is Uplink mode, TPID is 0x8100.
The dot1q-tunnel mode of the set interface 1/3 is Normal mode, TPID is 0x8100.
The dot1q-tunnel mode of the set interface 1/4 is Normal mode, TPID is 0x8100.
The dot1q-tunnel mode of the set interface 1/5 is Normal mode, TPID is 0x8100.
The dot1q-tunnel mode of the set interface 1/6 is Normal mode, TPID is 0x8100.
The dot1q-tunnel mode of the set interface 1/7 is Normal mode, TPID is 0x8100.
.
.
.
.
The dot1q-tunnel mode of the set interface 1/24 is Normal mode, TPID is 0x8100.
Console#
Содержание 6128PL2
Страница 2: ......
Страница 8: ...viii ...
Страница 26: ...Contents xviii ...
Страница 30: ...Tables xxii ...
Страница 52: ...Initial Configuration 2 10 2 ...
Страница 308: ...Configuring the Switch 3 256 3 ...
Страница 473: ...SNMP Commands 4 165 4 ...
Страница 644: ...Command Line Interface 4 336 4 ...
Страница 648: ...Software Specifications A 4 A ...
Страница 663: ......