User's Manual

Table Of Contents
The secondary-vlan-list parameter can contain multiple community VLAN IDs and one isolated VLAN
ID.
Enter a secondary-vlan-list or use the add keyword with a secondary-vlan-list to associate secondary
VLANs with a primary VLAN.
Use the remove keyword with a secondary-vlan-list to clear the association between secondary VLANs
and a primary VLAN.
You change the association between a secondary and primary VLAN by removing the existing association
and then adding the desired association.
If you delete either the primary or secondary VLAN, the VLAN becomes inactive on the port where the
association is configured. When you enter the no private-vlan command, the VLAN returns to the normal
VLAN mode. All primary and secondary associations on that VLAN are suspended, but the interfaces remain
in PVLAN mode. If you again convert the specified VLAN to PVLAN mode, the original associations are
reinstated.
If you enter the no vlan command for the primary VLAN, all PVLAN associations with that VLAN are lost.
However, if you enter the no vlan command for a secondary VLAN, the PVLAN associations with that VLAN
are suspended and are reinstated when you recreate the specified VLAN and configure it as the previous
secondary VLAN.
Before You Begin
Ensure that the PVLAN feature is enabled.
Procedure
PurposeCommand or Action
Enters configuration mode.switch# configure terminal
Step 1
Enters the number of the primary VLAN that you are
working in for the PVLAN configuration.
switch(config)# vlan primary-vlan-id
Step 2
Associates the secondary VLANs with the primary
VLAN. Use the remove keyword with a
switch(config-vlan)# private-vlan
association {[add] secondary-vlan-list
| remove secondary-vlan-list}
Step 3
secondary-vlan-list to clear the association between
secondary VLANs and a primary VLAN.
(Optional)
Removes all associations from the primary VLAN and
returns it to normal VLAN mode.
switch(config-vlan)# no private-vlan
association
Step 4
This example shows how to associate community VLANs 100 through 110 and isolated VLAN 200 with
primary VLAN 5:
switch# configure terminal
switch(config)# vlan 5
switch(config-vlan)# private-vlan association 100-110, 200
Cisco Nexus 3000 NX-OS Layer 2 Switching Configuration Guide, Release 5.0(3)U3(1)
44 OL-26590-01
Configuring Private VLANs
Associating Secondary VLANs with a Primary Private VLAN