C
HAPTER
36
| VLAN Commands
Configuring Private VLANs
– 852 –
To configure private VLANs, follow these steps:
1. Use the private-vlan command to designate one or more community
VLANs and the primary VLAN that will channel traffic outside of the
community groups.
2. Use the private vlan association command to map the community
VLAN(s) to the primary VLAN.
3. Use the switchport mode private-vlan command to configure ports as
promiscuous (i.e., having access to all ports in the primary VLAN) or
host (i.e., community port).
4. Use the switchport private-vlan host-association command to assign a
port to a community VLAN.
5. Use the switchport private-vlan mapping command to assign a port to a
primary VLAN.
6. Use the show vlan private-vlan command to verify your configuration
settings.
Table 100: Private VLAN Commands
Command Function Mode
Edit Private VLAN Groups
private-vlan Adds or deletes primary or community VLANs VC
private vlan association Associates a community VLAN with a primary VLAN VC
Configure Private VLAN Interfaces
switchport mode private-
vlan
Sets an interface to host mode or promiscuous mode IC
switchport private-vlan
host-association
Associates an interface with a secondary VLAN IC
switchport private-vlan
mapping
Maps an interface to a primary VLAN IC
Display Private VLAN Information
show vlan private-vlan Shows private VLAN information NE, PE