Previous Topic

Next Topic

Book Contents

Book Index

Private VLANs

A Private VLAN is a security feature that separates a regular VLAN domain into two or more subdomains. Each subdomain is represented by a primary VLAN and a secondary VLAN. The primary VLAN ID is the same for all subdomains that belong to a private VLAN. The secondary VLAN ID differentiates subdomains from each another and provides Layer 2 isolation between ports that are members of the same private VLAN.

Private VLANs are typically implemented in the network’s DMZ to protect network servers and other resources. Servers should not communicate with each other; however, the servers must communicate with a router in order to be accessed by network users. When using private VLANs, the servers are connected to the private VLAN host ports, and the routers connect to promiscuous ports. Then, if one of the servers is compromised, the intruder cannot use it to attack another server in the same network segment.

The same traffic isolation can be achieved by configuring each port with a different VLAN, allocating an IP subnet for each VLAN, and enabling L3 routing between them. However, the subnet-based VLAN approach requires more VLANs and IP subnets as well as L3 routing configuration. In a private VLAN domain, all members can share a common address space of a single subnet which is associated with a primary VLAN. So, the advantage of the private VLANs feature is that it reduces the number of consumed VLANs, improves IP addressing space utilization, and helps to avoid L3 routing.

There are the following types of VLANs within a private VLAN:

Three types of port designations exist within a private VLAN:

Private VLAN Type Configuration

Use the Private VLAN Type Configuration page to configure an existing VLAN as a Primary, Isolated, or Community VLAN. To access the Private VLAN Type Configuration page, click Switching > Private VLAN > Type Configuration in the navigation menu. By default, the type for all VLANs is Unconfigured.

Private VLAN Type Configuration

Private VLAN Type Configuration

Field

Description

VLAN ID

Identifies the VLAN ID of the VLAN configured on the switch.

Private VLAN Type

Select the type of private VLAN:

  • Primary - Sets Private VLAN as Primary Type
  • Isolated - Sets Private VLAN as Isolated Type
  • Community - Sets Private VLAN as Isolated Type
  • Unconfigured - Sets the VLAN as non Private VLAN

Private VLAN Association Configuration

Use the Private VLAN Association Configuration page to associate Isolated and Community VLANs with a Primary VLAN. To access the Private VLAN Association Configuration page, click Switching > Private VLAN > Association Configuration in the navigation menu.

Private VLAN Association Configuration

Private VLAN Association Configuration

Field

Description

Primary VLAN

Select the VLAN to use as the Primary VLAN ID of the domain. This VLAN is used to associate Secondary (Community and Isolated) VLANs to a domain.

Isolated VLAN

Shows the ID of the VLAN associated to the domain as the Isolated VLAN.

Community VLAN(s)

Displays the current Community VLAN IDs associated to the domain (through Primary VLAN). This field displays all the VLANs of type Secondary.

If you change any information on the page, click Submit to apply the changes to the system.

Private VLAN Association Summary

Use the Private VLAN Association Summary page to view associations between primary, Isolated, and Community VLANs. To access the Private VLAN Association Summary page, click Switching > Private VLAN > Association Summary in the navigation menu.

Private VLAN Association Summary

Private VLAN Association Summary

Field

Description

Primary VLAN

Shows the VLAN that is the Primary VLAN ID of the domain.

Isolated VLAN

Shows the ID of the VLAN associated to the domain as the Isolated VLAN.

Community VLAN

Shows the IDs of the community VLANs associated to the domain through the primary VLAN. This field displays all the VLANs of type Secondary.

Private VLAN Interface Configuration

Use the Private VLAN Interface Configuration page to configure the private VLAN mode for ports. To access the Private VLAN Interface Configuration page, click Switching > Private VLAN > Interface Configuration in the navigation menu.

Private VLAN Interface Configuration

Private VLAN Interface Configuration

Field

Description

Interface

Select the port to configure.

Switch Port Mode

Select the private VLAN mode for the selected port, which can be one of the following:

  • General - Sets port in General Mode
  • Host - Sets port in Host Mode. Used for Private VLAN configuration
  • Promiscuous - Sets port in Promiscuous Mode Used for Private VLAN configuration

Host Primary VLAN

Specify the primary VLAN ID for Host Association Mode.

Host Secondary VLAN

Specify the secondary VLAN ID for Host Association Mode.

Promiscuous Primary VLAN

Specify the primary VLAN ID for Promiscuous Association Mode.

Promiscuous Secondary VLAN ID(s)

Specify the secondary VLAN ID List for Promiscuous Association Mode. This field can accept a single VLAN ID or range of VLAN IDs, or a combination of both in sequence separated by ','.

NOTE: The VLAN ID List specified in this field will replace the configured Secondary VLAN list in the association.

Command Buttons

Private VLAN Interface Association Summary

Use the Private VLAN Interface Association Summary page to view associations between the private VLAN IDs and the ports. To access the Private VLAN Interface Association Summary page, click Switching > Private VLAN > Interface Association Summary in the navigation menu.

Private VLAN Interface Association Summary

Private VLAN Interface Association Summary

Field

Description

Interface

Identifies the port.

Switch Port Mode

Shows the private VLAN mode for the port, which can be one of the following:

  • General - Sets port in General Mode.
  • Host - Sets port in Host Mode. Used for Private VLAN configuration.
  • Promiscuous - Sets port in Promiscuous Mode. Used for Private VLAN configuration.

Host Primary VLAN

Shows the primary VLAN ID for Host Association Mode

Host Secondary VLAN

Shows the secondary VLAN ID for Host Association Mode.

Promiscuous Primary VLAN

Shows the primary VLAN ID for Promiscuous Association Mode.

Promiscuous Secondary VLAN ID(s)

Shows the secondary VLAN ID List for Promiscuous Association Mode.

Click Refresh to update the page with the most recent information from the system.

See Also

Configuring Switching Information

Configuring DHCP Snooping

Managing VLANs

Double VLAN (DVLAN) Tunneling

Configuring Protected Ports

Managing Protocol-Based VLANs

Managing IP Subnet-Based VLANs

Managing MAC-Based VLANs

Voice VLAN Configuration

Creating MAC Filters

Configuring GARP

Configuring Dynamic ARP Inspection

Configuring IGMP Snooping

Configuring IGMP Snooping Queriers

Configuring MLD Snooping

Configuring MLD Snooping Queriers

Creating Port Channels

Viewing Multicast Forwarding Database Information

Configuring Spanning Tree Protocol

Mapping 802.1p Priority

Configuring Port Security

Managing LLDP

Dot1ad Provider Bridging

Dot1ag Connectivity Fault Management (CFM)

Operations and Management

Priority-Based Flow Control

802.1AS

Multiple Registration Protocol Configuration