150 CN4093 Application Guide for N/OS 8.4
Protocol-Based VLANs
Protocol‐basedVLANs(PVLANs)allowyoutosegmentnetworktrafficaccording
tothenetworkprotocolsinuse.Trafficforsupportednetworkprotocolscanbe
confinedtoaparticularport‐basedVLAN.Youcangivedifferentprioritylevelsto
trafficgeneratedbydifferentnetworkprotocols.
WithPVLAN,theswitchclassifiesincomingpackets
byEthernetprotocolofthe
packets,notbytheconfigurationoftheingressport.Whenanuntaggedor
priority‐taggedframe arrivesataningressport,theprotocolinformationcarriedin
theframeisused todetermineaVLANtowhichtheframebelongs.Ifaframe’s
protocolisnotrecognized
asapre‐definedPVLANtype,theingressport’sPVIDis
assignedtotheframe.Whenataggedframearrives,theVLANIDintheframe’s
tagisused.
EachVLANcancontainuptoeightdifferentPVLANs.Youcanconfigureseparate
PVLANsondifferentVLANs,witheachPVLANsegmentingtraffic
forthesame
protocoltype.Forexample,youcanconfigurePVLAN1onVLAN2tosegment
IPv4traffic,andPVLAN 8onVLAN100tosegmentIPv4traffic.
TodefineaPVLANonaVLAN,configureaPVLANnumber(1‐8)andspecifythe
frametypeandtheEthernettype
ofthePVLANprotocol.Youmustassignatleast
oneporttothePVLANbeforeitcanfunction.DefinethePVLANframetypeand
Ethernettypeasfollows:
Frametype—consistsofoneofthefollowingvalues:
Ether2(EthernetII)
SNAP(SubnetworkAccessProtocol)
LLC(LogicalLinkControl)
Ethernettype—consistsofa4‐digit(16bit)hexvaluethatdefinestheEthernet
type.YoucanusecommonEthernetprotocolvalues,ordefineyourownvalues.
FollowingareexamplesofcommonEthernetprotocolvalues:
IPv4=0800
IPv6=86dd
ARP=0806
Port-Based vs. Protocol-Based VLANs
EachVLANsupportsbothport‐basedandprotocol‐basedassociation,asfollows:
ThedefaultVLANconfigurationisport‐based.Alldataportsaremembersof
VLAN1,withnoPVLANassociation.
WhenyouaddportstoaPVLAN,theportsbecomemembersofboththe
port‐basedVLANandthePVLAN.Forexample,ifyouaddportEXT1to
PVLAN1onVLAN2,theportalsobecomesamemberofVLAN2.
WhenyoudeleteaPVLAN,it’smemberportsremainmembersofthe
port‐basedVLAN.Forexample,ifyoudeletePVLAN1fromVLAN2,port
EXT1remainsamemberofVLAN2.
WhenyoudeleteaportfromaVLAN,theportisdeletedfromallcorresponding
PVLANs.