102
Forbidden VLANs
A port may be configured to never be member of one or more VLANs. This is particularly useful
when dynamic VLAN protocols like MVRP and GVRP must be prevented from dynamically
adding ports to VLANs. The trick is to mark such VLANs as forbidden on the port in question.
The syntax is identical to the syntax used in the Existing VLANs field. By default, the field is
left blank, which means that the port may become a member of all possible VLANs.
Private VLANs
In a private VLAN, communication between ports in that private VLAN is not permitted. The VLAN membership configuration
for the selected stack switch unit switch can be monitored and modified here. Up to 4096 VLANs are supported. This
page allows for adding and deleting VLANs as well as adding and deleting port members of each VLAN.
To configure the Private VLAN membership in the web interface:
Click Configuration / Private VLANs / Membership
Specify management VLAN ID. From 0 to 4094.
Click Apply and click the Save icon in the upper right corner to save the settings or click Reset to cancel. The
Form will return to the previously saved settings.
Private VLAN Configuration Parameters:
Items
Description
Delete
To delete a private VLAN entry, check this box. The entry will be deleted during the next save.
PVLAN ID
Indicates the ID of the private VLAN
Adding a new Private
VLAN
Click to add a new VLAN ID. An empty row is added to the table, and the VLAN can be
configured as needed. Legal values for a VLAN ID are 1 through 4095. The VLAN is enabled on
the selected stack switch unit when you click on "Save". The VLAN is thereafter present on
the other stack switch units, but with no port members. The check box is greyed out when
VLAN is displayed on other stacked switches, but user can add member ports to it. A VLAN
without any port members on any stack unit will be deleted when you click "Save". The
button can be used to undo the addition of new VLANs.
Private VLAN Port Isolation
Port Isolation provides for an apparatus and method to isolate ports on layer 2 switches on the same VLAN in order to
restrict traffic flow. The apparatus comprises a switch having plurality of ports, each port configured as a protected port or a
non-protected port. An address table stores an address table having a destination address and port number pair. A
forwarding map generator generates a forwarding map which is responsive to a destination address of a data packet. The
method for isolating ports on a layer 2 switch configures each of the ports on the layer 2 switch as a protected port or a non-
protected port. A destination address on a data packet is matched with a physical address on said layer 2 switch and a
forwarding map is generated for the data packet based upon the destination address of the data packet. The data packet is
then sent to the plurality of ports pursuant to the forwarding map generated based upon whether the ingress port was
configured as a protected or non-protected port.
To Configure Port Isolation in the web interface:
Click Configure / Private VLANs / Port Isolation
Select with port will be enabled for Port Isolation.
Click Apply and click the Save icon in the upper right corner to save the settings or click Reset to cancel. The
Form will return to the previously saved settings.