Afeature of private VLANs across multiple switches is that traffic from an isolated port in switch A does not
reachan isolatedport on SwitchB.
Figure 7: Private VLANs Across Switches
BecauseVTP does not support private VLANs, you must manually configure private VLANs on all switches
inthe Layer 2 network. If you do not configure the primary and secondary VLAN association in some switches
inthe network, the Layer 2 databases in these switches are not merged. This can result in unnecessary flooding
ofprivate VLAN trafficon those switches.
Private VLAN Interaction with Other Features

Private VLANs and Unicast, Broadcast, and Multicast Traffic

Inregular VLANs, devicesin thesame VLAN cancommunicate with each other at the Layer 2 level,but
devicesconnected to interfaces in different VLANs must communicate at the Layer 3 level. In private VLANs,
thepromiscuous ports are members of the primary VLAN, while the host ports belong to secondary VLANs.
Becausethe secondary VLAN is associated to the primary VLAN, members of the these VLANs can
communicatewith each other at the Layer 2 level.
Ina regular VLAN, broadcasts are forwarded to all ports in that VLAN. Private VLAN broadcast forwarding
dependson the port sending the broadcast:
Anisolated port sends a broadcast only to the promiscuous ports or trunk ports.
Acommunity port sends a broadcast to all promiscuous ports, trunk ports, and ports in the same
communityVLAN.
Apromiscuous port sends a broadcast to all ports inthe private VLAN (other promiscuous ports, trunk
ports,isolated ports, and community ports).
Catalyst 2960-XR Switch VLAN Configuration Guide, Cisco IOS Release 15.0(2)EX1
OL-29440-01 91
Configuring Private VLANs
Private VLAN Interaction with Other Features