User Manual
UMN:CLI
V5824G
225
lated ports except traffic from promiscuous ports. Traffic from isolated port is for-
warded only to promiscuous ports.
•
Community
: Community ports communicate among themselves and with their pro-
miscuous ports. These interfaces are separated at Layer 2 from all other interfaces in
other communities or isolated ports within their PVLAN.
The difference between Private VLAN and Private VLAN edge is that PVLAN edge
guarantees security for the ports in a VLAN using protected port and PVLAN guarantees
port security by creating sub-VLAN with the three types (Promiscuous, Isolation, and
Community). And because PVLAN edge can work on local switch, the isolation between
two switches is impossible.
The V5824G provides Private VLAN function like Private VLAN edge of Cisco product.
Because it does not create any sub-VLAN, port security is provided by port isolation. If
you want to configure Private VLAN on the V5824G switch, refer to Port Isolation
configuration.
8.1.10.1
Port Isolation
The Port Isolation feature is a method that restricts L2 switching between isolated ports in
a VLAN. However, flows between isolated port and non-isolated port are not restricted. If
you use the
port protected
command, packet cannot be transmitted between protected
ports. However, to non-protected ports, communication is possible.
To configure Port Isolation, use the following command.
Command
Mode
Description
port protected
PORTS
Bridge
Enables port isolation.
no port protected
[
PORTS
]
Disables port isolation.
To display the configured port isolation, use the following command.
Command
Mode
Description
show port protected
Enable
Global
Bridge
Shows port isolation configuration.
8.1.10.2
Shared VLAN
This chapter is only for Layer 2 switch operation. The V5824G is Layer 3 switch, but it can
be used for Layer 2 also. Because there is no routing information in Layer 2 switch, each
VLAN cannot communicate. Especially, the uplink port should receive packets from all
VLANs. Therefore, when you configure the V5824G as Layer 2 switch, the uplink ports
must be included in all VLANs.