Figure 22-2. Configuring VLANs for a Private VLAN
FTOS#conf
FTOS(conf)# interface vlan 10
FTOS(conf-vlan-10)# private-vlan mode primary
FTOS(conf-vlan-10)# private-vlan mapping secondary-vlan 100-101
FTOS(conf-vlan-10)# untagged TenGig 2/1
FTOS(conf-vlan-10)# tagged TenGig 2/3
FTOS(conf)# interface vlan 101
FTOS(conf-vlan-101)# private-vlan mode community
FTOS(conf-vlan-101)# untagged TenGig 2/10
FTOS(conf)# interface vlan 100
FTOS(conf-vlan-100)# private-vlan mode isolated
FTOS(conf-vlan-100)# untagged Te 2/2
Private VLAN Configuration Example
Figure 22-3. Sample Private VLAN Topology
The following configuration is based on the
On MXL 10/40GbE Switch:
•
TenGig 0/0 and TenGig 0/23 are configured as promiscuous ports, assigned to the primary VLAN,
VLAN 4000.
•
TenGig 0/25 is configured as a PVLAN trunk port, also assigned to the primary VLAN 4000.
•
TenGig 0/24 and TenGig 0/47 are configured as host ports and assigned to the isolated VLAN, VLAN
4003.
•
TenGig 4/0 and TenGig 0/23 are configured as host ports and assigned to the community VLAN,
VLAN 4001.
•
TenGig 4/24 and TenGig 4/47 are configured as host ports and assigned to community VLAN 4002.
Figure
22-3:
Private VLANs (PVLAN) | 397