154 CN4093 Application Guide for N/OS 8.4
Configuration Guidelines
ThefollowingguidelinesapplywhenconfiguringPrivateVLANs:
ManagementVLANscannotbePrivateVLANs.Managementportscannotbe
membersofaPrivateVLAN.
ThedefaultVLAN1cannotbeaPrivateVLAN.
IGMPSnoopingmustbedisabledonPrivateVLANs.
AllVLANsthatcomprisethePrivateVLANmustbelongtothesameSpanning
TreeGroup.
AVLANpairisaprimaryVLANandoneassociatedsecondaryVLAN(isolated
orcommunity).ThemaximumnumberofVLANpairsperportis16.
Configuration Example
FollowthisproceduretoconfigureaPrivateVLAN.
1. SelectaVLANanddefinethePrivateVLANtypeasprimary.
2. ConfigureapromiscuousportforVLAN700.
3. ConfiguretwosecondaryVLANs:isolatedVLANandcommunityVLAN.
4. MapsecondaryVLANstoprimaryVLAN.
CN 4093(config)# vlan 700
CN 4093(config-vlan)# private-vlan primary
CN 4093(config-vlan)# exit
CN 4093(config)# interface port 1
CN 4093(config-if)# switchport mode private-vlan
CN 4093(config-if)# switchport private-vlan mapping 700
CN 4093(config-if)# exit
CN 4093(config)# vlan 701
CN 4093(config-vlan)# private-vlan isolated
CN 4093(config-vlan)# exit
CN 4093(config)# vlan 702
CN 4093(config-vlan)# private-vlan community
CN 4093(config-vlan)# exit
CN 4093(config)# vlan 700-702
CN 4093(config-vlan)# stg 1
CN 4093(config-vlan)# exit
CN 4093(config)# vlan 700
CN 4093(config-vlan)# private-vlan association 701,702
CN 4093(config-vlan)# exit