System information
Cisco Cat3K ST 6 June 2012
53
TOE SFRs How the SFR is Met
isolated host ports that belong to the secondary VLANs associated with
the primary VLAN.
• Isolated—An isolated port is a host port that belongs to an isolated
secondary VLAN. It has complete Layer 2 separation from other ports
within the same private VLAN, except for the promiscuous ports.
Private VLANs block all traffic to isolated ports except traffic from
promiscuous ports. Traffic received from an isolated port is forwarded
only to promiscuous ports.
• Community—A community port is a host port that belongs to a
community secondary VLAN. Community ports communicate with
other ports in the same community VLAN and with promiscuous ports.
These interfaces are isolated at Layer 2 from all other interfaces in
other communities and from isolated ports within their private VLAN.
Primary and secondary VLANs have these characteristics:
• Primary VLAN—A PVLAN has only one primary VLAN. Every port
in a PVLAN is a member of the primary VLAN. The primary VLAN
carries unidirectional traffic downstream from the promiscuous ports to
the (isolated and community) host ports and to other promiscuous
ports.
• Isolated VLAN —A PVLAN has only one isolated VLAN. An isolated
VLAN is a secondary VLAN that carries unidirectional traffic