37
Private VLAN (PVLAN)
The private VLAN (PVLAN) feature of the Dell Force10 operating software (FTOS) is supported on the C-Series, S-Series,
Z-Series, or S4810 platforms.
Private VLANs extend the FTOS security suite by providing Layer 2 isolation between ports within the same private
VLAN. A private VLAN partitions a traditional VLAN into subdomains identified by a primary and secondary VLAN pair.
The FTOS private VLAN implementation is based on RFC 3069.
For more information, refer to the following commands. The command output is augmented in FTOS version 7.8.1.0 at
later to provide PVLAN data:
•
show arp
•
show vlan
Private VLAN Concepts
Primary VLAN:
The primary VLAN is the base VLAN and can have multiple secondary VLANs. There are two types of secondary VLAN
— community VLAN and isolated VLAN:
•
A primary VLAN can have any number of community VLANs and isolated VLANs.
•
Private VLANs block all traffic to isolated ports except traffic from promiscuous ports. Traffic received from an
isolated port is forwarded only to promiscuous ports or trunk ports.
Community VLAN:
A community VLAN is a secondary VLAN of the primary VLAN:
•
Ports in a community VLAN can talk to each other. Also, all ports in a community VLAN can talk to all
promiscuous ports in the primary VLAN and vice-versa.
•
Devices on a community VLAN can communicate with each other using member ports, while devices in an
isolated VLAN cannot.
Isolated VLAN:
An isolated VLAN is a secondary VLAN of the primary VLAN:
•
Ports in an isolated VLAN cannot talk to each other. Servers would be mostly connected to isolated VLAN ports.
•
Isolated ports can talk to promiscuous ports in the primary VLAN, and vice-versa.
Port Types:
•
Community port
: A community port is a port that belongs to a community VLAN and is allowed to communicate
with other ports in the same community VLAN and with promiscuous ports.
•
Isolated port
: An isolated port is a port that, in Layer 2, can only communicate with promiscuous ports that are in
the same PVLAN.
•
Promiscuous port
: A promiscuous port is a port that is allowed to communicate with any other port type.
1157
Summary of Contents for Force10 Z9000
Page 1: ...FTOS Command Line Reference Guide for the Z9000 System FTOS 9 1 0 0 ...
Page 96: ...96 ...
Page 194: ...194 ...
Page 312: ...312 ...
Page 540: ...540 ...
Page 546: ...546 ...
Page 560: ...560 ...
Page 566: ...566 ...
Page 590: ...action act UpdateCounter param0 1 0x01 param1 0 0x00 output truncated 590 ...
Page 624: ...624 ...
Page 638: ...638 ...
Page 648: ...648 ...
Page 659: ...Related Commands show gvrp displays the GVRP configuration 659 ...
Page 660: ...660 ...
Page 834: ...834 ...
Page 854: ...854 ...
Page 906: ...906 ...
Page 914: ...914 ...
Page 976: ...976 ...
Page 990: ...990 ...
Page 1006: ...1006 ...
Page 1008: ...1008 ...
Page 1026: ...1026 ...
Page 1145: ...10 211 1 2 Outgoing interface list GigabitEthernet 8 0 1145 ...
Page 1146: ...1146 ...
Page 1156: ...1156 ...
Page 1166: ...1166 ...
Page 1180: ...1180 ...
Page 1258: ...1258 ...
Page 1272: ...1272 ...
Page 1394: ...1394 ...
Page 1400: ...1400 ...
Page 1410: ...1410 ...
Page 1424: ...1424 ...
Page 1444: ...1444 ...
Page 1468: ...Version 8 3 8 0 Introduced on the S4810 1468 ...
Page 1470: ...1470 ...