Private Vlan - Cisco 350XG series Administration Manual

10g stackable managed switches
Table of Contents

Advertisement

VLAN Management
Overview
Cisco 350XG & 550XG Series 10G Stackable Managed Switches

Private VLAN

The Private VLAN feature provides layer-2 isolation between ports. This means
that at the level of bridging traffic, as opposed to IP routing, ports that share the
same Broadcast domain cannot communicate with each other. The ports in a
private VLAN can be located anywhere in the layer 2 network, meaning that they
do not have to be on the same switch. The private VLAN is designed to receive
untagged or priority-tagged traffic and transmit untagged traffic.
The following types of ports can be members in a private VLAN:
Promiscuous—A promiscuous port can communicate with all ports of the
same private VLAN. These ports connect servers and routers.
Community (host)—Community ports can define a group of ports that are
member in the same Layer 2 domain. They are isolated at Layer 2 from
other communities and from isolated ports. These ports connect host ports.
Isolated (host)—An isolated port has complete Layer 2 isolation from the
other isolated and community ports within the same private VLAN. These
ports connect host ports.
The following types of private VLANs exist:
Primary VLAN—The primary VLAN is used to enable Layer 2 connectivity
from promiscuous ports to isolated and to community ports. There can only
be a single primary VLAN per private VLAN.
Isolated VLAN (also known as a Secondary VLAN)—An isolated VLAN is
used to enable isolated ports to send traffic to the primary VLAN. There can
only be a single, isolated VLAN per private VLAN.
Community VLAN (also known as a Secondary VLAN)—To create a sub-
group of ports (community) within a VLAN, the ports must be added a
community VLAN. The community VLAN is used to enable Layer 2
connectivity from community ports to promiscuous ports and to community
ports of the same community. There can be a single community VLAN for
each community and multiple community VLANs can coexist in the system
for the same private VLAN).
See
Figure 1
and
Figure 2
Host traffic is sent on isolated and community VLANs, while server and router
traffic is sent on the primary VLAN.
for samples of how these VLANs are used.
12
224

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

550xg series

Table of Contents