CHAPTER
34-1
Software Configuration Guide—Release 12.2(25)SG
OL-76590-03
34
Configuring Private VLANs
This chapter describes private VLANs (PVLANs) on Catalyst4500 series switches. It also provides
restrictions, procedures, and configuration examples.
This chapter includes the following major sections:
Overview of PVLANs, page 34-1
How to Configure PVLANs, page 34-3
Note For complete syntax and usage information for the switch commands used in this chapter, refer to the
Catalyst 4500 Series Switch Cisco IOS Command Reference and related publications at
http://www.cisco.com/univercd/cc/td/doc/product/software/ios122/122cgcr/index.htm.

Overview of PVLANs

PVLANs provide Layer2 isolation between ports within the same PVLAN. There are three types of
PVLAN ports:
Promiscuous—A promiscuous port can communicate with all inter faces, including the isolated and
community ports within a PVLAN.
Isolated—An isolated port has complete Layer 2 separation from the other ports within the same
PVLAN, but not from the promiscuous ports. PVLANs block all traffic to isolated ports except
traffic from promiscuous ports. Traffic from isolated port is forwarded only to promiscuous ports.
Community—Community ports communicate among themselves and with their promiscuous ports.
These interfaces are separated at Layer 2 from all other interfaces in other communities or isolated
ports within their PVLAN.
Because trunks can support the VLANs carrying traffic between isolated, community, and promiscuous
ports, isolated and community port traffic might enter or leave the switch through a trunk interface.
PVLAN ports are associated with a set of supporting VLA Ns that are used to create the PVLAN
structure. A PVLAN uses VLANs three ways:
As a primary VLAN—Carries traffic from promiscuous ports to isolated, community, and other
promiscuous ports in the same primary VLAN.
As an isolated VLAN—Carries traffic from isolated ports to a prom iscuous port.
As a community VLAN—Carries traffic between community ports an d to promiscuous ports. You
can configure multiple community VLANs in a PVLAN.