12-12
Cisco ME 3400 EthernetAccess Switch SoftwareConfiguration Guide
78-17058-01
Chapter12 Configuring Private VLANs
Configuring Private VLANs
Configuring a Layer 2 Interface as a Private-VLAN Host Port
Beginning in privileged EXEC mode, follow these steps to configure a Layer 2 in terfa ce a s a
private-VLAN host port and to associate it with primary and second ary V L ANs:
Note Isolated and community VLANs are both secondary V LAN s.
This example shows how to configure an interface as a private-VLAN host port, associate it with a
private-VLAN pair, and verify the configuration:
Switch# configure terminal
Switch(config)# interface fastethernet0/22
Switch(config-if)# no shutdown
Switch(config-if)# switchport mode private-vlan host
Switch(config-if)# switchport private-vlan host-association 20 25
Switch(config-if)# end
Switch# show interfaces fastethernet0/22 switchport
Name: Fa0/22
Switchport: Enabled
Administrative Mode: private-vlan host
Operational Mode: private-vlan host
Administrative Trunking Encapsulation: dot1q
Operational Trunking Encapsulation: native
Negotiation of Trunking: Off
Access Mode VLAN: 1 (default)
Trunking Native Mode VLAN: 1 (default)
Administrative Native VLAN tagging: enabled
Administrative private-vlan host-association: 20 (VLAN0020) 25 (VLAN0025)
Administrative private-vlan mapping: none
Administrative private-vlan trunk native VLAN: none
Administrative private-vlan trunk Native VLAN tagging: enabled
Administrative private-vlan trunk encapsulation: dot1q
Administrative private-vlan trunk normal VLANs: none
Administrative private-vlan trunk private VLANs: none
Operational private-vlan:
20 (VLAN0020) 25 (VLAN0025)
<output truncated>
Command Purpose
Step1 configure terminal Enter global configuration mode.
Step2 interface interface-id Enter interface configuration mode for the Layer 2
interface to be configured.
Step3 no shutdown Enable the port, if necessary. By default, UNIs are
disabled, and NNIs are enabled.
Step4 switchport mode private-vlan host Configure the Layer 2 port as a private-VLAN host port.
Step5 switchport private-vlan host-association
primary_vlan_id secondary_vlan_id Associate the Layer 2 port with a private VLAN.
Step6 end Return to privileged EXEC mode.
Step7 show interfaces [interface-id] switchport Verify the configuration.
Step8 copy running-config startup config (Optional) Save your entries in the switch startup
configuration file.