Zyxel XS3700-24 [234/371] Private vlan

Zyxel XS3700-24 [234/371] Private vlan
Chapter 61 Private VLAN Commands
Ethernet Switch CLI Reference Guide
234
This example sets a private VLAN rule (pvlan-111) that applies to VLAN 111. Ports 1, 2 and
24 belong to VLAN 111. Ports 1 and 2 are added to the isolated port list automatically and
cannot communicate with each other. Port 24 is the uplink port and also the promiscuour port
in this VLAN. The isolated ports in VLAN 111 can send and receive traffic from the uplink
port 24. This example also shows all private VLAN rules configured on the
Switch.
61.2 Private VLAN
Use Private VLAN if you want you to block traffic between ports in the same VLAN.
Community and Isolated VLANs are secondary private VLANs that must be associated with
a Primary private VLAN.
Primary: Ports in a Primary VLAN are promiscuous and they can communicate with all
promiscuous ports in the same primary VLAN, and all ports in associated community and
isolated VLANs. They cannot communicate with ports in different primary VLANs.
Community: Ports in a Community VLAN can communicate with promiscuous ports in an
associated Primary VLAN and other community ports in the same Community VLAN. They
cannot communicate with ports in Isolated VLANs, non-associated Primary VLAN
promiscuous ports nor community ports in different Community VLANs.
Isolated: Ports in an Isolated VLAN can communicate with promiscuous ports in an
associated Primary VLAN only. They cannot communicate with other isolated ports in the
same Isolated VLAN, non-associated Primary VLAN promiscuous ports nor any
community ports.
Tagged private VLANs can span switches but trunking ports must be VLAN-trunking ports.
61.2.1 Command Summary
The following section lists the commands for this feature.
sysname# configure
sysname(config)# private-vlan name pvlan-111 vlan 111
sysname(config)# exit
sysname# show private-vlan
Private VLAN: 111 Active: Yes
Name Promiscuous Port
------------ --------------------------
pvlan-111 24
sysname#
Table 148 private-vlan Command Summary
COMMAND DESCRIPTION M P
vlan <vlan-id> Enters config-vlan mode for the specified VLAN. Creates the
VLAN, if necessary.
C13
private-vlan <primary |
isolated | community>
Configures the specified VLAN as a Primary VLAN, Isolated
VLAN or a Community VLAN.
C13

Содержание

Скачать