Chapter 36 Configuring Private Vlans; Overview Of Pvlans - Cisco 4500M Software Manual

Software guide
Table of Contents

Advertisement

Configuring Private VLANs
This chapter describes private VLANs (PVLANs) on Catalyst 4500 series switches. It also provides
restrictions, procedures, and configuration examples.
This chapter includes the following major sections:
For complete syntax and usage information for the switch commands used in this chapter, refer to the
Note
Catalyst 4500 Series Switch Cisco IOS Command Reference and related publications at
http://www.cisco.com/univercd/cc/td/doc/product/software/ios122/122cgcr/index.htm.

Overview of PVLANs

PVLANs provide Layer 2 isolation between ports within the same PVLAN. There are three types of
PVLAN ports:
Because trunks can support the VLANs carrying traffic between isolated, community, and promiscuous
ports, isolated and community port traffic might enter or leave the switch through a trunk interface.
PVLAN ports are associated with a set of supporting VLANs that are used to create the PVLAN
structure. A PVLAN uses VLANs three ways:
OL-6696-01
Overview of PVLANs, page 36-1
How to Configure PVLANs, page 36-3
Promiscuous—A promiscuous port can communicate with all interfaces, including the isolated and
community ports within a PVLAN.
Isolated—An isolated port has complete Layer 2 separation from the other ports within the same
PVLAN, but not from the promiscuous ports. PVLANs block all traffic to isolated ports except
traffic from promiscuous ports. Traffic from isolated port is forwarded only to promiscuous ports.
Community—Community ports communicate among themselves and with their promiscuous ports.
These interfaces are separated at Layer 2 from all other interfaces in other communities or isolated
ports within their PVLAN.
As a primary VLAN—Carries traffic from promiscuous ports to isolated, community, and other
promiscuous ports in the same primary VLAN.
As an isolated VLAN—Carries traffic from isolated ports to a promiscuous port.
As a community VLAN—Carries traffic between community ports and to promiscuous ports. You
can configure multiple community VLANs in a PVLAN.
C H A P T E R
Software Configuration Guide—Release 12.2(25)EW
36
36-1

Advertisement

Table of Contents
loading

This manual is also suitable for:

4500 series

Table of Contents