Pvlan Configuration - Zte ZXR10 2900E series Configuration Manual

Easy-maintenance secure switch
Hide thumbs Also See for ZXR10 2900E series:
Table of Contents

Advertisement

ZXR10 2900E Series Configuration Guide
Queue 2 Shaping Rate (Kbps) : No-Limit
Queue 3 Shaping Rate (Kbps) : No-Limit
Queue 4 Shaping Rate (Kbps) : No-Limit
Queue 5 Shaping Rate (Kbps) : No-Limit
Queue 6 Shaping Rate (Kbps) : No-Limit
Queue 7 Shaping Rate (Kbps) : No-Limit
zte(cfg)#sho qos traffic-limit port 1
Port Ingress Traffic Limit Table:
Flags: DataRate - traffic limit rate (Kbps), BcEn - Enable Broadcast Limit
PORT
-------
port-1

5.13 PVLAN Configuration

PVLAN Overview
To enhance network security, it is necessary to isolate users' packets. A traditional solution
is to allocate a VLAN for a user. This solution has obvious limits, as described below.
1. IEEE 802.1Q standard supports 4094 VLANs at most. The number of users is limited,
which is not good for network extension.
2. Each VLAN corresponds to an IP subnet. Too many subnets bring IP address waste.
3. Too many VLANs and IP subnets make it difficult to manage networks.
The Private VLAN (PVLAN) technology solves these problems.
A PVLAN divides ports in a VLAN into hybrid ports, isolated ports, and community ports.
l
A hybrid port can communicate with any port.
l
An isolated port can communicate only with a hybrid port, and it cannot communicate
with other isolated ports.
l
A community port can communicate with a hybrid port or another community port in
the same session.
The ports within a VLAN are separated. Users can only communicate with their default
gateways, and the network security is guaranteed.
The ZXR10 2900E series switches support four PVLAN sessions. Each PVLAN session
supports an unlimited number of hybrid ports. Each PVLAN supports an unlimited number
of isolated or community ports.
Configuring PVLAN
The PVLAN configuration includes the following commands:
SJ-20130731155059-002|2013-11-27 (R1.0)
KucEn - Enable Known unicast Limit, McEn - Enable Multicast Limit
TcpSynEn - Enable TCP SYN Limit, UucEn - Enable Unknown unicast Limit
DataRate(Kbps)
BcEn
--------------
-----
2000
1
The Burst Size
The Burst Size
The Burst Size
The Burst Size
The Burst Size
The Burst Size
KucEn
McEn
TcpSynEn
------
-----
---------
1
1
1
5-60
ZTE Proprietary and Confidential
: N/A
: N/A
: N/A
: N/A
: N/A
: N/A
UucEn
------
1

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents