VLAN Commands

4-235

4
Example

Configuring Private VLANs

Private VLANs provide port-based security and isolation of local ports contained
within different private VLAN groups. This switch supports two types of private
VLANs – primary and community groups. A primary VLAN contains promiscuous
ports that can communicate with all other ports in the associated private VLAN
groups, while a community (or secondary) VLAN contains community ports that can
only communicate with other hosts within the community VLAN and with any of the
promiscuous ports in the associated primary VLAN. The promiscuous ports are
designed to provide open access to an external network such as the Internet, while
the community ports provide restricted access to local users.
Multiple primary VLANs can be configured on this switch, and multiple community
VLANs can be associated with each primary VLAN. (Note that private VLANs and
normal VLANs can exist simultaneously within the same switch.)
This section describes commands used to configure private VLANs.
Console#show pvlan
Private VLAN status: Enabled
Up-link port:
Ethernet 1/12
Down-link port:
Ethernet 1/5
Ethernet 1/6
Ethernet 1/7
Ethernet 1/8
Console#
Table 4-74 Private VLAN Commands
Command Function Mode Page
Edit Private VLAN Groups
private-vlan Adds or deletes primary or community VLANs VC 4-233
private-vlan association Associates a community VLAN with a primary VLAN VC 4-234
Configure Private VLAN Interfaces
switchport mode
private-vlan
Sets an interface to host mode or promiscuous mode IC 4-238
switchport private-vlan
host-association
Associates an interface with a secondary VLAN IC 4-238
switchport private-vlan
mapping
Maps an interface to a primary VLAN IC 4-239
Display Private VLAN Information
show vlan private-vlan Shows private VLAN information NE,
PE
4-239