Technical data

BLADE OS 5.1 Application Guide
BMD00136, November 2009 Chapter 3: VLANs
61
5. Enable the PVLAN.
6. Verify PVLAN operation.
Private VLANs
Private VLANs provide Layer 2 isolation between the ports within the same broadcast domain.
Private VLANs can control traffic within a VLAN domain, and provide port-based security for host
servers.
Use Private VLANs to partition a VLAN domain into sub-domains. Each sub-domain is comprised
of one primary VLAN and one or more secondary VLANs, as follows:
Primary VLAN—carries unidirectional traffic downstream from promiscuous ports. Each
Private VLAN configuration has only one primary VLAN. All ports in the Private VLAN are
members of the Primary VLAN.
Secondary VLAN—Secondary VLANs are internal to a private VLAN domain, and are
defined as follows:
Isolated VLAN—carries unidirectional traffic upstream from the host servers toward ports
in the primary VLAN and the gateway. Each Private VLAN configuration can contain only
one isolated VLAN.
Community VLAN—carries upstream traffic from ports in the community VLAN to other
ports in the same community, and to ports in the primary VLAN and the gateway. Each
Private VLAN can contain multiple community VLANs.
After you define the primary VLAN and one or more secondary VLANs, you map the secondary
VLAN(s) to the primary VLAN.
RS G8000 (config-vlan)# protocol-vlan 1 enable
RS G8000 (config)# show protocol-vlan
PVLAN Protocol FrameType EtherType Priority Status Ports
----- -------- -------------------- -------- ------ -----------
1 2 ether2 0800 2 ena 1, 2
PVLAN PVLAN-Tagged Ports
----- ---------------------------
1 1, 2