Specifications
4.7 PrivateVLAN
TheprivateVLANhelpstoresolvetheprimaryVLANIDshortage,clientports’
isolationandnetworksecurityissues.ThePrivateVLANprovidesprimaryand
secondaryVLANwithinasingleswitch.
PrimaryVLAN:TheuplinkportisusuallytheprimaryVLAN.AprimaryVLAN
containspromiscuousportsthatcancommunicatewithlowerSecondaryVLANs.
SecondaryVLAN:TheclientportsareusuallydefinedwithinsecondaryVLAN.The
secondaryVLANincludesIsolatedVLANandCommunityVLAN.Theclientports
canbeisolatedVLANsorcanbegroupedinthesameCommunityVLAN.The
portswithinthesamecommunityVLANcancommunicatewitheachother.
However,theisolatedVLANportscanNot.
ThefigureshowsthetypicalPrivateVLANnetwork.TheSCADA/PublicServeror
NMSworkstationisusuallylocatedinprimaryVLAN.TheclientsPCsorRingsare
locatedwithinSecondary.
PrivateVLAN(PVLAN)ConfigurationgroupenablesyoutoConfigurePVLAN,
PVLANPortandseethePVLANInformation.
Followingcommandsareincludedinthisgroup:
4.7.1PVLANConfiguration
4.7.2PVLANPortConfiguration
4.7.3CLICommandsofthePVLAN
4.7.1 PVLANConfiguration
PVLANConfigurationallowsyoutoassignPrivateVLANtype.AftercreatedVLAN
inVLANConfiguraitonpage,theavailableVLANIDwilldisplayhere.Choosethe
PrivateVLANtypesforeachVLANyouwantconfigure.
None:TheVLANisNotincludedinPrivateVLAN.
Primary:TheVLANisthePrimaryVLAN.Thememberportscancommunicate
withsecondaryports.
Isolated:TheVLANistheIsolatedVLAN.ThememberportsoftheVLANare
isolated.
Community:TheVLANistheCommunityVLAN.ThememberportsoftheVLAN
93