12-11
Cisco ME 3400 EthernetAccess Switch SoftwareConfiguration Guide
78-17058-01
Chapter12 Configuring Private VLANs Configuring Private VLANs
When you associate secondary VLANs with a primary VLAN, note this syntax information:
The secondary_vlan_list parameter cannot contain spaces. It can co ntain multiple co mma-separa ted
items. Each item can be a single private-VLAN ID or a hyphenated rang e of private-VLAN ID s.
The secondary_vlan_list parameter can contain multiple c om mun ity V L AN IDs but only on e
isolated VLAN ID.
Enter a secondary_vlan_list, or use the add keyword with a secondary_vlan_ list to associate
secondary VLANs with a primary VLAN.
Use the remove keyword with a secondary_vlan_list to clear the association between secondary
VLANs and a primary VLAN.
The private-vlan association VLAN configuration command does not ta ke effect u nt il you exit
VLAN configuration mode.
This example shows how to configure VLAN 20 as a primary VLAN, VLAN 501 as an isolat ed VLAN,
and VLANs 502 and 503 as community VLANs, to a ssociate them in a private VLAN, and to verify the
configuration. It assumes that VLANs 502 and 503 have previously been configured as UNI c ommunity
VLANs:
Switch# configure terminal
Switch(config)# vlan 20
Switch(config-vlan)# private-vlan primary
Switch(config-vlan)# exit
Switch(config)# vlan 501
Switch(config-vlan)# private-vlan isolated
Switch(config-vlan)# exit
Switch(config)# vlan 502
Switch(config-vlan)# no-uni vlan
Switch(config-vlan)# private-vlan community
Switch(config-vlan)# exit
Switch(config)# vlan 503
Switch(config-vlan)# no-uni vlan
Switch(config-vlan)# private-vlan community
Switch(config-vlan)# exit
Switch(config)# vlan 20
Switch(config-vlan)# private-vlan association 501-503
Switch(config-vlan)# end
Switch(config)# show vlan private vlan
Primary Secondary Type Ports
------- --------- ----------------- ------------------------------------------
20 501 isolated
20 502 community
20 503 community
20 504 non-operational