VLAN Commands

4-233

4

Configuring Port-based Traffic Segmentation

If tighter security is required for passing traffic from different clients through downlink
ports on the local network and over uplink ports to the service provider, port-based
traffic segmentation can be used to isolate traffic for individual clients.
Local traffic belonging to each client is isolated to the allocated downlink ports, and
upstream traffic coming from the downlink ports can only be forwarded to, and from,
uplink ports.
This section describes commands used to configure traffic segmentation.

pvlan

This command enables port-based traffic segmentation. Use the no form to disable
this feature.
Syntax
[no] pvlan
Default Setting
Disabled
Command Mode
Global Configuration
Command Usage
When traffic segmentation is enabled, the forwarding state for the uplink and
downlink ports is shown below.
When traffic segmentation is disabled, all ports operate in normal forwarding
mode based on the settings specified by other functions such as VLANs and
spanning tree protocol.
Table 4-72 Traffic Segmentation Commands
Command Function Mode Page
pvlan Enables traffic segmentation GC 4-233
pvlan up-link/down-link Configures uplink/downlink ports for client sessions GC 4-234
show pvlan Displays the configured private VLANS PE 4-234
Table 4-73 Traffic Segmentation Forwarding
Destination
Source
Downlinks Uplinks Normal Ports
Downlink Ports Blocking Forwarding Blocking
Uplink Ports Forwarding Forwarding Forwarding
Normal Ports Forwarding Forwarding Forwarding