C
HAPTER
35
| VLAN Commands
Configuring VLAN Interfaces
– 836 –
COMMAND USAGE
â—† Ingress filtering only affects tagged frames.
â—† If ingress filtering is disabled and a port receives frames tagged for
VLANs for which it is not a member, these frames will be flooded to all
other ports (except for those VLANs explicitly forbidden on this port).
â—† If ingress filtering is enabled and a port receives frames tagged for
VLANs for which it is not a member, these frames will be discarded.
â—† Ingress filtering does not affect VLAN independent BPDU frames, such
as GVRP or STA. However, they do affect VLAN dependent BPDU
frames, such as GMRP.
EXAMPLE
The following example shows how to set the interface to port 1 and then
enable ingress filtering:
Console(config)#interface ethernet 1/1
Console(config-if)#switchport ingress-filtering
Console(config-if)#
switchport mode This command configures the VLAN membership mode for a port. Use the
no form to restore the default.
SYNTAX
switchport mode {access | hybrid | trunk}
no switchport mode
access - Specifies an access VLAN interface. The port transmits and
receives untagged frames on a single VLAN only.
hybrid - Specifies a hybrid VLAN interface. The port may transmit
tagged or untagged frames.
trunk - Specifies a port as an end-point for a VLAN trunk. A trunk is
a direct link between two switches, so the port transmits tagged
frames that identify the source VLAN. Note that frames belonging to
the port’s default VLAN (i.e., associated with the PVID) are also
transmitted as tagged frames.
DEFAULT SETTING
All ports are in access mode with the PVID set to VLAN 1.
COMMAND MODE
Interface Configuration (Ethernet, Port Channel)
COMMAND USAGE
Access mode is mutually exclusive with VLAN trunking (see the vlan-
trunking command). If VLAN trunking is enabled on an interface, then that
interface cannot be set to access mode, and vice versa.