Associating Primary And Secondary Vlans; Broadcast Traffic In Private Vlans; Private Vlan Port Isolation - Cisco Nexus 7000 Series Configuration Manual

Nx-os layer 2 switching
Hide thumbs Also See for Nexus 7000 Series:
Table of Contents

Advertisement

Private VLAN Overview

Associating Primary and Secondary VLANs

To allow the host ports in secondary VLANs to communicate outside the private VLAN, you associate
secondary VLANs to the primary VLAN. If the association is not operational, the host ports (isolated and
community ports) in the secondary VLAN are brought down.
You can associate a secondary VLAN with only one primary VLAN.
Note
For an association to be operational, the following conditions must be met:
• The primary VLAN must exist.
• The secondary VLAN must exist.
• The primary VLAN must be configured as a primary VLAN.
• The secondary VLAN must be configured as either an isolated or community VLAN.
If you delete either the primary or secondary VLAN, the ports that are associated with the VLAN become
inactive. When you reconvert the specified VLAN to private VLAN mode, the original associations are
reinstated.
If the association is not operational on private VLAN trunk ports, only that VLAN goes down, not the entire
port.
This behavior is different from how Catalyst devices work.
Note
In order to change the association between a secondary and primary VLAN, you must first remove the current
association and then add the desired association.

Broadcast Traffic in Private VLANs

Broadcast traffic from ports in a private VLAN flows in the following ways:
• The broadcast traffic flows from all promiscuous ports to all ports in the primary VLAN. This broadcast
traffic is distributed to all ports within the primary VLAN, including those ports that are not configured
with private VLAN parameters.
• The broadcast traffic from all isolated ports is distributed only to those promiscuous ports in the primary
VLAN that are associated to that isolated port.
• The broadcast traffic from community ports is distributed to all ports within the port's community and
to all promiscuous ports that are associated to the community port. The broadcast packets are not
distributed to any other communities within the primary VLAN or to any isolated ports.

Private VLAN Port Isolation

You can use private VLANs to control access to end stations as follows:
Cisco Nexus 7000 Series NX-OS Layer 2 Switching Configuration Guide, Release 5.x
58
Configuring Private VLANs Using NX-OS

Advertisement

Table of Contents
loading

Table of Contents