© Copyright Lenovo 2017
Chapter 8: VLANs
153
Private VLANs
Private
VLANs
provide
Layer
2
isolation
between
the
ports
within
the
same
broadcast
domain.
Private
VLANs
can
control
traffic
within
a
VLAN
domain,
and
provide
port
‐
based
security
for
host
servers.
Enterprise
NOS
supports
Private
VLAN
configuration
as
described
in
RFC
5517.
Use
Private
VLANs
to
partition
a
VLAN
domain
into
sub
‐
domains.
Each
sub
‐
domain
is
comprised
of
one
primary
VLAN
and
one
secondary
VLAN,
as
follows:
Primary
VLAN—carries
unidirectional
traffic
downstream
from
promiscuous
ports.
Each
Private
VLAN
has
only
one
primary
VLAN.
All
ports
in
the
Private
VLAN
are
members
of
the
primary
VLAN.
Secondary
VLAN—Secondary
VLANs
are
internal
to
a
private
VLAN
domain,
and
are
defined
as
follows:
Isolated
VLAN—carries
unidirectional
traffic
upstream
from
the
host
servers
toward
ports
in
the
primary
VLAN.
Each
Private
VLAN
can
contain
only
one
Isolated
VLAN.
Community
VLAN—carries
upstream
traffic
from
ports
in
the
community
VLAN
to
other
ports
in
the
same
community,
and
to
ports
in
the
primary
VLAN.
Each
Private
VLAN
can
contain
multiple
community
VLANs.
After
you
define
the
primary
VLAN
and
one
or
more
secondary
VLANs,
you
map
the
secondary
VLAN(s)
to
the
primary
VLAN.
Private VLAN Ports
Private
VLAN
ports
are
defined
as
follows:
Promiscuous—A
promiscuous
port
is
a
port
that
belongs
to
the
primary
VLAN.
The
promiscuous
port
can
communicate
with
all
the
interfaces,
including
ports
in
the
secondary
VLANs
(Isolated
VLAN
and
Community
VLANs).
Isolated—An
isolated
port
is
a
host
port
that
belongs
to
an
isolated
VLAN.
Each
isolated
port
has
complete
layer
2
separation
from
other
ports
within
the
same
private
VLAN
(including
other
isolated
ports),
except
for
the
promiscuous
ports.
Traffic
sent
to
an
isolated
port
is
blocked
by
the
Private
VLAN,
except
the
traffic
from
promiscuous
ports.
Traffic
received
from
an
isolated
port
is
forwarded
only
to
promiscuous
ports.
Community—A
community
port
is
a
host
port
that
belongs
to
a
community
VLAN.
Community
ports
can
communicate
with
other
ports
in
the
same
community
VLAN,
and
with
promiscuous
ports.
These
interfaces
are
isolated
at
layer
2
from
all
other
interfaces
in
other
communities
and
from
isolated
ports
within
the
Private
VLAN.
Summary of Contents for Flex System Fabric CN4093
Page 27: ... Copyright Lenovo 2017 27 Part 1 Getting Started ...
Page 28: ...28 CN4093 Application Guide for N OS 8 4 ...
Page 58: ...58 CN4093 Application Guide for N OS 8 4 ...
Page 72: ...72 CN4093 Application Guide for N OS 8 4 ...
Page 85: ... Copyright Lenovo 2017 85 Part 2 Securing the Switch ...
Page 86: ...86 CN4093 Application Guide for N OS 8 4 ...
Page 98: ...98 CN4093 Application Guide for N OS 8 4 ...
Page 112: ...112 CN4093 Application Guide for N OS 8 4 ...
Page 136: ...136 CN4093 Application Guide for N OS 8 4 ...
Page 156: ...156 CN4093 Application Guide for N OS 8 4 ...
Page 192: ...192 CN4093 Application Guide for N OS 8 4 ...
Page 228: ...228 CN4093 Application Guide for N OS 8 4 ...
Page 229: ... Copyright Lenovo 2017 229 Part 4 Advanced Switching Features ...
Page 230: ...230 CN4093 Application Guide for N OS 8 4 ...
Page 298: ...298 CN4093 Application Guide for N OS 8 4 ...
Page 382: ...382 CN4093 Application Guide for N OS 8 4 ...
Page 392: ...392 CN4093 Application Guide for N OS 8 4 ...
Page 416: ...416 CN4093 Application Guide for N OS 8 4 ...
Page 452: ...452 CN4093 Application Guide for N OS 8 4 ...
Page 466: ...466 CN4093 Application Guide for N OS 8 4 ...
Page 496: ...496 CN4093 Application Guide for N OS 8 4 ...
Page 508: ...508 CN4093 Application Guide for N OS 8 4 ...
Page 510: ...510 CN4093 Application Guide for N OS 8 4 ...
Page 514: ...514 CN4093 Application Guide for N OS 8 4 ...
Page 538: ...538 CN4093 Application Guide for N OS 8 4 ...
Page 539: ... Copyright Lenovo 2017 539 Part 7 Network Management ...
Page 540: ...540 CN4093 Application Guide for N OS 8 4 ...
Page 554: ...554 CN4093 Application Guide for N OS 8 4 ...
Page 576: ...576 CN4093 Application Guide for N OS 8 4 ...
Page 596: ...596 CN4093 Application Guide for N OS 8 4 ...
Page 604: ...604 CN4093 Application Guide for N OS 8 4 ...
Page 609: ... Copyright Lenovo 2017 609 Part 9 Appendices ...
Page 610: ...610 CN4093 Application Guide for N OS 8 4 ...
Page 626: ...626 CN4093 Application Guide for N OS 8 4 ...
Page 633: ......
Page 634: ...Part Number 00MY375 Printed in USA IP P N 00MY375 ...