PromiscuousApromiscuous port belongs to the primary VLAN and can communicate with all interfaces,
includingthe community and isolated host ports that belong to the secondary VLANs associated with
theprimary VLAN.
IsolatedAnisolated port is a host port that belongs to an isolated secondary VLAN. It has complete
Layer2 separation from other ports within the same private VLAN, except for the promiscuous ports.
PrivateVLANs block all traffic to isolated ports except traffic from promiscuous ports. Traffic received
froman isolated port is forwarded only to promiscuous ports.
CommunityAcommunity port is a host port that belongs to a community secondary VLAN. Community
portscommunicate with other ports in the same community VLAN and with promiscuous ports. These
interfacesare isolated at Layer 2 fromall other interfaces in othercommunities and from isolated ports
withintheir private VLAN.
Trunkports carry traffic from regular VLANs and also from primary, isolated, and community VLANs.Note
Primaryand secondary VLANs have these characteristics:
PrimaryVLANA private VLAN has only one primary VLAN. Every port in a private VLAN is a
memberof the primary VLAN. The primary VLAN carries unidirectional trafficdownstream from the
promiscuousports to the (isolated and community) host ports and to other promiscuous ports.
IsolatedVLAN A private VLAN has only one isolated VLAN. An isolated VLAN is a secondary
VLANthat carries unidirectional traffic upstream from the hosts toward the promiscuous ports and the
gateway.
CommunityVLANA community VLAN is a secondary VLAN that carries upstream traffic from the
communityports to the promiscuous port gateways and to other host ports in the same community. You
canconfigure multiple community VLANs in a private VLAN.
Apromiscuous port can serve only one primary VLAN, one isolated VLAN, and multiple community VLANs.
Layer3 gateways are typically connected to the switch through a promiscuous port. With a promiscuous port,
youcan connect a wide range of devices as access points to a private VLAN. For example, you can use a
promiscuousport to monitor or back up all the private VLAN servers from an administration workstation.
Related Topics
Configuringa Layer 2 Interface as a Private VLAN Host Port, on page 96
Example:Configuring an Interface as a Host Port, on page 102
Configuringa Layer 2 Interface as a Private VLAN Promiscuous Port, on page 98
Example:Configuring an Interface as a Private VLAN Promiscuous Port, on page 103
Private VLANs in Networks
Ina switched environment, you can assign an individual private VLAN and associated IP subnet to each
individualor common group of end stations. The end stations need to communicate only with a default gateway
tocommunicate outside the private VLAN.
Youcan use private VLANs to control access to end stations in these ways:
Catalyst 2960-XR Switch VLAN Configuration Guide, Cisco IOS Release 15.0(2)EX1
OL-29440-01 89
Configuring Private VLANs
Private VLANs in Networks