C
HAPTER
36
| VLAN Commands
Configuring VLAN Interfaces
– 1136 –
switchport
ingress-filtering
This command enables ingress filtering for an interface. Use the no form to
restore the default.
SYNTAX
[no] switchport ingress-filtering
DEFAULT SETTING
Disabled
COMMAND MODE
Interface Configuration (Ethernet, Port Channel)
COMMAND USAGE
â—† Ingress filtering only affects tagged frames.
â—† If ingress filtering is disabled and a port receives frames tagged for
VLANs for which it is not a member, these frames will be flooded to all
other ports (except for those VLANs explicitly forbidden on this port).
â—† If ingress filtering is enabled and a port receives frames tagged for
VLANs for which it is not a member, these frames will be discarded.
â—† Ingress filtering does not affect VLAN independent BPDU frames, such
as GVRP or STA. However, they do affect VLAN dependent BPDU
frames, such as GMRP.
EXAMPLE
The following example shows how to set the interface to port 1 and then
enable ingress filtering:
Console(config)#interface ethernet 1/1
Console(config-if)#switchport ingress-filtering
Console(config-if)#
switchport mode This command configures the VLAN membership mode for a port. Use the
no form to restore the default.
SYNTAX
switchport mode {access | hybrid | trunk}
no switchport mode
access - Specifies an access VLAN interface. The port transmits and
receives untagged frames on a single VLAN only.
hybrid - Specifies a hybrid VLAN interface. The port may transmit
tagged or untagged frames.
trunk - Specifies a port as an end-point for a VLAN trunk. A trunk is
a direct link between two switches, so the port transmits tagged
frames that identify the source VLAN. Note that frames belonging to