switchport forbidden vlan
The switchport forbidden vlan Interface Configuration mode command forbids adding specific VLANs to a port.
To return to the default configuration, use the remove parameter for this command.
Syntax
switchport forbidden vlan {add vlan-list | remove vlan-list}
Parameters
•
add vlan-list — Specifies the list of VLAN IDs to be added. Separate nonconsecutive VLAN IDs with a comma
and no spaces. A hyphen designates a range of IDs.
•
remove vlan-list — Specifies the list of VLAN IDs to be removed. Separate nonconsecutive VLAN IDs with a
comma and no spaces. A hyphen designates a range of IDs.
Default Configuration
All VLANs are allowed.
Command Mode
Interface Configuration (Ethernet, port-channel) mode
User Guidelines
This command can be used to prevent GVRP from automatically making the specified VLANs active on the
selected ports.
Example
The following example forbids adding VLAN IDs 234 to 256 to Ethernet port 6.
Console(config)# interface ethernet 6
Console(config-if)# switchport forbidden vlan add 234-256
Page 304
VLAN Commands