Chapter 14 Private Vlans; Information About Private Vlans; Private Vlan Domains; Spanning Multiple Switches - Cisco Nexus 1000V Troubleshooting Manual

Switch for vmware vsphere. release 5.2(1)sv3(1.1)
Hide thumbs Also See for Nexus 1000V:
Table of Contents

Advertisement

Private VLANs
This chapter describes how to identify and resolve problems related to private VLANs and includes the
following sections:

Information About Private VLANs

Private VLANs (PVLANs) are used to segregate Layer 2 Internet service provider (ISP) traffic and
convey it to a single router interface. PVLANs achieve device isolation by applying Layer 2 forwarding
constraints that allow end devices to share the same IP subnet while being Layer 2 isolated. The use of
larger subnets reduces address management overhead. Three separate port designations are used. Each
has its own unique set of rules that regulate each connected endpoint's ability to communicate with other
connected endpoints within the same private VLAN domain.

Private VLAN Domains

A private VLAN domain consists of one or more pairs of VLANs. The primary VLAN makes up the
domain, and each VLAN pair makes up a subdomain. The VLANs in a pair are called the primary VLAN
and the secondary VLAN. All VLAN pairs within a private VLAN have the same primary VLAN. The
secondary VLAN ID is what differentiates one subdomain from another.

Spanning Multiple Switches

Private VLANs can span multiple switches, just like regular VLANs. Inter-switch link ports do not need
to be aware of the special VLAN type and can carry frames tagged with these VLANs as like they do
with any other frames. Private VLANs ensure that traffic from an isolated port in one switch does not
reach another isolated or community port in a different switch even after traversing an inter-switch link.
By embedding the isolation information at the VLAN level and by transporting it along with the packet,
you can maintain consistent behavior throughout the network. The mechanism that restricts Layer 2
communication between two isolated ports in the same switch also restricts Layer 2 communication
between two isolated ports in two different switches.
OL-31593-01
Information About Private VLANs, page 14-1
Troubleshooting Guidelines, page 14-2
Private VLAN Troubleshooting Commands, page 14-2
C H A P T E R
Cisco Nexus 1000V Troubleshooting Guide, Release 5.2(1)SV3(1.1)
14
14-1

Advertisement

Table of Contents
loading

Table of Contents