4 Command Line Interface

Configuring Private VLANs

Private VLANs provide port-based security and isolation between ports within the assigned VLAN. This switch supports two types of private VLAN ports: promiscuous, and community ports. A promiscuous port can communicate with all interfaces within a private VLAN. Community ports can only communicate with other ports in their own community VLAN, and with their designated promiscuous ports. This section describes commands used to configure private VLANs.

Table 4-54. Private VLAN Commands

Command

Function

Mode

Page

Edit Private VLAN Groups

 

 

 

 

 

 

 

private-vlan

Adds or deletes primary and secondary VLANs

VC

4-155

 

 

 

 

private-vlan association

Associates a secondary VLAN with a primary VLAN

VC

4-156

 

 

 

 

Configure Private VLAN Interfaces

 

 

 

 

 

 

switchport mode

Sets an interface to host mode or promiscuous mode

IC

4-156

private-vlan

 

 

 

switchport private-vlan

Associates an interface with a secondary VLAN

IC

4-157

host-association

 

 

 

switchport private-vlan

Maps an interface to a primary VLAN

IC

4-158

mapping

 

 

 

Display Private VLAN Information

 

 

 

 

 

 

show vlan private-vlan

Shows private VLAN information

NE,

4-158

 

 

PE

 

To configure private VLANs, follow these steps:

1.Use the private-vlancommand to designate one or more community VLANs and the primary VLAN that will channel traffic outside the community groups.

2.Use the private-vlan association command to map the secondary (i.e., community) VLAN(s) to the primary VLAN.

3.Use the switchport mode private-vlancommand to configure ports as promiscuous (i.e., having access to all ports in the primary VLAN) or host (i.e., having access restricted to community VLAN members, and channeling all other traffic through a promiscuous port).

4.Use the switchport private-vlan host-association command to assign a port to a secondary VLAN.

5.Use the switchport private-vlan mapping command to assign a port to a primary VLAN.

6.Use the show vlan private-vlancommand to verify your configuration settings.

4-154

Page 330
Image 330
SMC Networks 100BASE-TX, 16 10BASE-T manual Configuring Private VLANs, Private Vlan Commands Function Mode