4 Command Line Interface

Configuring Private VLANs

Private VLANs provide port-based security and isolation between ports within the assigned VLAN. This switch supports two types of private VLANs: primary/ secondary associated groups, and stand-alone isolated VLANs. A primary VLAN contains promiscuous ports that can communicate with all other ports in the private VLAN group, while a secondary (or community) VLAN contains community ports that can only communicate with other hosts within the secondary VLAN and with any of the promiscuous ports in the associated primary VLAN. Isolated VLANs, on the other hand, consist a single stand-alone VLAN that contains one promiscuous port and one or more isolated (or host) ports. In all cases, the promiscuous ports are designed to provide open access to an external network such as the Internet, while the community or isolated ports provide restricted access to local users.

Multiple primary VLANs can be configured on this switch, and multiple community VLANs can be associated with each primary VLAN. One or more isolated VLANs can also be configured. (Note that private VLANs and normal VLANs can exist simultaneously within the same switch.)

This section describes commands used to configure private VLANs.

Table 4-60 Private VLAN Commands

Command

Function

Mode

Page

Edit Private VLAN Groups

 

 

 

 

 

 

 

private-vlan

Adds or deletes primary and secondary VLANs

VC

4-189

 

 

 

 

private-vlan association

Associates a secondary VLAN with a primary VLAN

VC

4-190

 

 

 

 

Configure Private VLAN Interfaces

 

 

 

 

 

 

switchport mode

Sets an interface to host mode or promiscuous mode

IC

4-191

private-vlan

 

 

 

switchport private-vlan

Associates an interface with a secondary VLAN

IC

4-191

host-association

 

 

 

switchport private-vlan

Associates an interface with an isolated VLAN

IC

4-192

isolated

 

 

 

switchport private-vlan

Maps an interface to a primary VLAN

IC

4-193

mapping

 

 

 

Display Private VLAN Information

 

 

 

 

 

 

show vlan private-vlan

Shows private VLAN information

NE,

4-194

 

 

PE

 

To configure primary/secondary associated groups, follow these steps:

1.Use the private-vlancommand to designate one or more community VLANs and the primary VLAN that will channel traffic outside of the community groups.

2.Use the private-vlan association command to map the community VLAN(s) to the primary VLAN.

4-188

Page 430
Image 430
Accton Technology ES3526XA, ES3552XA manual Configuring Private VLANs, Private Vlan Commands