Configuring PVLANs
To configure a PVLAN, follow these steps:
Step 1 Set
VTP mode to transparent.
Step 2 Create the
secondary VLANs.
NOTE:
Isolated and community VLANs are secondary VLANs.
Step 3 Create the primary VLAN.
Step 4 Associate the secondary VLAN to the primary
VLAN.
NOTE:
Only one isolated VLAN can be mapped to a primary VLAN, but more than
one community VLAN can be mapped to a primary VLAN.
Step 5 Configure an interface to an isolated or
community port.
Step 6 Associate the isolated
port or community port to the primary-secondary VLAN pair.
Step 7 Configure an interface as a promiscuous
port.
Step 8 Map the promiscuous port to the
primary-secondary VLAN pair.
Use these commands to configure a
VLAN as a PVLAN:
Switch(config)#vlan
vlan_ID
Switch(config-vlan)#[no ]
private-vlan {isolated | primary }
Example: PVLAN Configurations
This example shows how to configure
VLAN202 as a primary VLAN and verify the configuration:
Switch#configure
terminal
Switch(config)#vlan
202
Switch(config-vlan)#private-vlan
primary
Switch(config-vlan)#end
Switch#show vlan private-vlan
type
Primary Secondary Type
Interfaces
- - - - - - -
202 primary
This example shows how to configure VLAN 200 as an isolated VLAN and verify
the configuration:
Switch#configure
terminal
Switch(config)#vlan 200
Switch(config-vlan)#private-vlan
isolated
Switch(config-vlan)#end
Switch#show vlan private-vlan
type
Primary Secondary Type
Interfaces
- - - - - - -
202 primary
200
isolated
To associate secondary VLANs with a primary
VLAN, perform this procedure:
Switch(config)#vlan
primary_vlan_ID
Switch(config-vlan)#[no ]
private -vlan
association {secondary_vlan_list | add
secondary_vlan_list | remove
secondary_vlan_list }
When you associate secondary VLANs with a primary VLAN, note the
following:
The
secondary_vlan_list
parameter contains only one
isolated VLAN ID.
Use the remove keyword with the
secondary_vlan_list
variable to clear the association between the secondary VLAN and the
primary VLAN. The list can contain only one VLAN.
Use the no keyword to clear all associations from the primary VLAN.
The command does not take effect until you exit VLAN configuration
submode.
Lab Activity
Lab
Exercise: Configuring Protected Ports
The student will configure Private VLAN Edge protected ports.