Cisco Systems N3KC3048TP1GE, N3KC3064TFAL3 manual Associating Primary and Secondary VLANs

Models: N3KC3064TFAL3 N3KC3048TP1GE

1 164
Download 164 pages 5.98 Kb
Page 54
Image 54
Associating Primary and Secondary VLANs

Configuring Private VLANs

Primary, Isolated, and Community Private VLANs

The following figure shows the traffic flows within a PVLAN, along with the types of VLANs and types of ports.

Figure 4: Private VLAN Traffic Flows

Note The PVLAN traffic flows are unidirectional from the host ports to the promiscuous ports. Traffic received on primary VLAN enforces no separation and forwarding is done as in a normal VLAN.

A promiscuous access port can serve only one primary VLAN and multiple secondary VLANs (community and isolated VLANs). With a promiscuous port, you can connect a wide range of devices as access points to a PVLAN. For example, you can use a promiscuous port to monitor or back up all the PVLAN servers from an administration workstation.

In a switched environment, you can assign an individual PVLAN and associated IP subnet to each individual or common group of end stations. The end stations need to communicate only with a default gateway to communicate outside the private VLAN.

Associating Primary and Secondary VLANs

To allow host ports in secondary VLANs to communicate outside the PVLAN, you associate secondary VLANs to the primary VLAN. If the association is not operational, the host ports (community and isolated ports) in the secondary VLAN are brought down.

Note You can associate a secondary VLAN with only one primary VLAN.

 

Cisco Nexus 3000 NX-OS Layer 2 Switching Configuration Guide, Release 5.0(3)U3(1)

40

OL-26590-01

Page 54
Image 54
Cisco Systems N3KC3048TP1GE, N3KC3064TFAL3 manual Associating Primary and Secondary VLANs