Cisco Nexus 7000 Series Configuration Manual page 78

Nx-os layer 2 switching
Hide thumbs Also See for Nexus 7000 Series:
Table of Contents

Advertisement

Secondary and Primary VLAN Configuration
• For nontrunking ports, note the following:
We recommend that you enable BPDU Guard on all ports that you configure as a host port; do not enable
Note
this feature on promiscuous ports.
• For private VLAN promiscuous trunk ports, note the following:
• For private VLAN isolated trunk ports, note the following:
• You can apply different Quality of Service (QoS) configurations to primary, isolated, and community
VLANs.
• To apply a VACL to all private VLAN traffic, map the secondary VLANs on the VLAN network interface
of the primary VLAN, and then configure the VACLs on the VLAN network interface of the primary
VLAN.
• The VACLs that you apply to the VLAN network interface of a primary VLAN automatically apply to
the associated isolated and community VLANs only after you have configured the mapping.
• If you do not map the secondary VLAN to the VLAN network interface of the primary VLAN, you can
have different VACLs for primary and secondary VLANs, which can cause problems.
• Because traffic in a private VLAN flows in different directions in different VLANs, you can have
different VACLs for ingressing traffic and different VACLs for egressing traffic prior to configuring
the mapping.
Cisco Nexus 7000 Series NX-OS Layer 2 Switching Configuration Guide, Release 5.x
62
◦ There is a separate instance of STP for each VLAN in the private VLAN.
◦ STP parameters for the primary and all secondary VLANs must match.
◦ The primary and all associated secondary VLANs should be in the same MST instance.
◦ STP is aware only of the primary VLAN for any private VLAN host port; STP does not run on
secondary VLANs on a host port.
• You can configure a maximum of 16 private VLAN primary and secondary VLAN pairs on each
promiscuous trunk port.
• The native VLAN must be either a normal VLAN or a private VLAN primary VLAN. You cannot
configure a private VLAN secondary VLAN as the native VLAN for a private VLAN promiscuous
trunk port.
• To downgrade a system that has private VLAN promiscuous trunk ports configured, you must
unconfigure these ports.
◦ You can configure a maximum of 16 private VLAN primary and secondary VLAN pairs on each
isolated trunk port.
◦ The native VLAN must be either a normal VLAN or a private VLAN secondary VLAN. You
cannot configure a private VLAN primary port as the native VLAN for a private VLAN isolated
trunk port.
◦ To downgrade a system that has private VLAN isolated trunk ports configured, you must
unconfigure these ports.
Configuring Private VLANs Using NX-OS

Advertisement

Table of Contents
loading

Table of Contents