Command Line Interface
4-322
4
Configuring Private VLANs
Private VLANs provide port-based security and isolation of local ports contained
within different private VLAN groups. This switch supports two types of private
VLANs – primary and community groups. A primary VLAN contains promiscuous
ports that can communicate with all other ports in the associated private VLAN
groups, while a community (or secondary) VLAN contains community ports that can
only communicate with other hosts within the community VLAN and with any of the
promiscuous ports in the associated primary VLAN. The promiscuous ports are
designed to provide open access to an external network such as the Internet, while
the community ports provide restricted access to local users.
Multiple primary VLANs can be configured on this switch, and multiple community
VLANs can be associated with each primary VLAN. (Note that private VLANs and
normal VLANs can exist simultaneously within the same switch.)
This section describes commands used to configure private VLANs.
To configure primary/community associated groups, follow these steps:
1.
Use the
private-vlan
command to designate one or more community VLANs
and the primary VLAN that will channel traffic outside of the community groups.
2.
Use the
private-vlan association
command to map the community VLAN(s) to
the primary VLAN.
3.
Use the
switchport mode private-vlan
command to configure ports as
promiscuous (i.e., having access to all ports in the primary VLAN) or host (i.e.,
community port).
4.
Use the
switchport private-vlan host-association
command to assign a port
to a community VLAN.
5.
Use the
switchport private-vlan mapping
command to assign a port to a
primary VLAN.
Table 4-81 Private VLAN Commands
Command
Function
Mode
Page
Edit Private VLAN Groups
private-vlan
Adds or deletes primary or community VLANs
VC
4-323
private-vlan association
Associates a community VLAN with a primary VLAN
VC
4-324
Configure Private VLAN Interfaces
switchport mode
private-vlan
Sets an interface to host mode or promiscuous mode
IC
4-324
switchport private-vlan
host-association
Associates an interface with a secondary VLAN
IC
4-325
switchport private-vlan
mapping
Maps an interface to a primary VLAN
IC
4-326
Display Private VLAN Information
show vlan private-vlan
Shows private VLAN information
NE,
PE
4-326
Содержание 6152PL2 FICHE
Страница 2: ......
Страница 6: ...vi ...
Страница 8: ...viii ...
Страница 32: ...Tables xxxii ...
Страница 38: ...Figures xxxviii ...
Страница 56: ...Initial Configuration 2 10 2 ...
Страница 378: ...Configuring the Switch 3 322 3 ...
Страница 651: ...Address Table Commands 4 273 4 Example Console show mac address table aging time Aging time 100 sec Console ...
Страница 817: ......
Страница 818: ...SMC6128PL2 SMC6152PL2 149100000007A R01 ...