Example Configuration - Allied Telesis SwitchBlade x908 Series Software Reference Manual

Switchblade x908/x900 series alliedware plus operating system software reference for version 5.3.1
Hide thumbs Also See for SwitchBlade x908 Series:
Table of Contents

Advertisement

Private VLANs operate within a single switch and comprise one primary VLAN plus a number
of secondary VLANS. All data enters the private VLAN ports untagged. Using the example of
figure
the host ports using VLAN 20, the primary VLAN. Data returning from the host ports to the
promiscuous port (and exiting the switch) use the secondary VLAN associated with its
particular host port, VLAN 21, 22, or 23 in the example. Thus the data flows into the switch via
the primary VLAN and out of the switch via the secondary VLANs. This situation is not
detected outside of the switch, because all its private ports are untagged. Note however, that
data flowing between ports within the same community VLAN will do so using the VID of the
community VLAN.
Portfast on Private VLANS
Within private VLANs, we recommend that you place all host ports into spanning-tree portfast
mode and enable BPDU guard. Portfast assumes that because host ports will also be edge
ports, they will have no alternative paths (loops) via other bridges. These ports are therefore
allowed to move directly from the spanning-tree blocking state into the forwarding state, thus
bypassing the intermediate states.
Applying BPDU guard is an extra precaution. This feature disables an edge port if it receives a
BPDU frame, because receiving such a frame would indicate that the port has a connection to
another network bridge.
For more information on BPDU guard and portfast, see their following commands:
spanning-tree portfast bpdu-filter command on page 19.41
spanning-tree portfast command on page 19.40

Example Configuration

Step 1:
Create the four VLANs 20 to 23.
Step 2:
Set the VLANs to be private and either primary, community, or isolated.
C613-50007-01 REV B
Figure
16-1, data enters the switch via the promiscuous port 1.0.1 and is forwarded to
Create the private VLANs
awplus#
awplus(config)#
awplus(config-vlan)#
Set the private VLAN types
awplus(config-vlan)#
awplus(config-vlan)#
awplus(config-vlan)#
awplus(config-vlan)#
Software Reference for SwitchBlade® x908, x900 and x600 Series Switches
TM
AlliedWare Plus
Operating System - Software Version 5.3.1
configure terminal
vlan database
vlan 20-23
private-vlan 20 primary
private-vlan 21 community
private vlan 22 community
private vlan 23 isolated
VLAN Introduction
16.11

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents