EasyManuals Logo

Cisco Catalyst 4500 Series Software Configuration Guide

Cisco Catalyst 4500 Series
2086 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #1226 background imageLoading...
Page #1226 background image
47-2
Catalyst 4500 Series Switch, Cisco IOS Software Configuration Guide - Cisco IOS XE 3.9.xE and IOS 15.2(5)Ex
Chapter 47 Configuring Private VLANs
About Private VLANs
Purpose of a PVLAN
Using PVLANs provides scalability and IP address management benefits for service providers and
Layer 2 security for customers. PVLANs partition a regular VLAN domain into subdomains. A
subdomain is represented by a pair of VLANs: a primary VLAN and a secondary VLAN. A PVLAN can
have multiple VLAN pairs, one pair for each subdomain. All VLAN pairs in a PVLAN share the same
primary VLAN. The secondary VLAN ID differentiates one subdomain from another. See Figure 47-1.
Figure 47-1 Private-VLAN Domain
The three types of secondary VLANs are as follows:
• Isolated VLANs—Ports within an isolated VLAN cannot communicate with each other at the
Layer 2 level.
• Community VLANs—Ports within a community VLAN can communicate with each other but
cannot communicate with ports in other communities at the Layer 2 level.
• Twoway-Community VLANs—Bidirectional VLAN. Ports within a twoway-community VLAN can
communicate with each other but not with communities or twoway-communities at the Layer 2 level.
Note Beginning with Cisco IOS Release 15.0(2)SG, you can use a twoway-community VLAN to
apply VACLs or QoS in both directions per-community and per-customer.
A promiscuous port can serve only one primary VLAN, one isolated VLAN, and multiple community
(or twoway-community) VLANs. Layer 3 gateways are typically connected to the switch through a
promiscuous port.
208744
Private
Private
VLAN
VLAN
domain
domain
Private
VLAN
domain
Primary
VLAN
SubdomainSubdomain
Secondary
community VLAN
SubdomainSubdomain
Secondary
community VLAN
Secondary
isolated VLAN or
Twoway-Community
VLAN
Secondary
isolated VLAN or
Twoway-Community
VLAN

Table of Contents

Other manuals for Cisco Catalyst 4500 Series

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Cisco Catalyst 4500 Series and is the answer not in the manual?

Cisco Catalyst 4500 Series Specifications

General IconGeneral
SeriesCatalyst 4500 Series
CategorySwitch
Layer SupportLayer 2, Layer 3
Form FactorModular chassis
StackableNo
Chassis Slots3, 6, 7, 10
Power Supply OptionsAC, DC
RedundancyPower supply, Supervisor engine
Network ManagementCisco IOS Software CLI, SNMP, Cisco Prime Infrastructure
FeaturesSecurity, QoS
Port DensityUp to 384 ports per chassis
Security Features802.1X, ACLs, DHCP Snooping, Dynamic ARP Inspection, IP Source Guard
Supervisor Engine8-E

Related product manuals