Chapter 12
Configuring Private VLANs
When you associate secondary VLANs with a primary VLAN, note this syntax information:
•
The secondary_vlan_list parameter cannot contain spaces. It can contain multiple comma-separated
items. Each item can be a single private-VLAN ID or a hyphenated range of private-VLAN IDs.
•
The secondary_vlan_list parameter can contain multiple community VLAN IDs but only one
isolated VLAN ID.
•
Enter a secondary_vlan_list, or use the add keyword with a secondary_vlan_list to associate
secondary VLANs with a primary VLAN.
•
Use the remove keyword with a secondary_vlan_list to clear the association between secondary
VLANs and a primary VLAN.
•
The private-vlan association VLAN configuration command does not take effect until you exit
VLAN configuration mode.
This example shows how to configure VLAN 20 as a primary VLAN, VLAN 501 as an isolated VLAN,
and VLANs 502 and 503 as community VLANs, to associate them in a private VLAN, and to verify the
configuration. It assumes that VLANs 502 and 503 have previously been configured as UNI community
VLANs:
Switch# configure terminal
Switch(config)# vlan 20
Switch(config-vlan)# private-vlan primary
Switch(config-vlan)# exit
Switch(config)# vlan 501
Switch(config-vlan)# private-vlan isolated
Switch(config-vlan)# exit
Switch(config)# vlan 502
Switch(config-vlan)# no-uni vlan
Switch(config-vlan)# private-vlan community
Switch(config-vlan)# exit
Switch(config)# vlan 503
Switch(config-vlan)# no-uni vlan
Switch(config-vlan)# private-vlan community
Switch(config-vlan)# exit
Switch(config)# vlan 20
Switch(config-vlan)# private-vlan association 501-503
Switch(config-vlan)# end
Switch(config)# show vlan private vlan
Primary Secondary Type
------- --------- ----------------- ------------------------------------------
20
20
20
20
78-17058-01
501
isolated
502
community
503
community
504
non-operational
Ports
Cisco ME 3400 Ethernet Access Switch Software Configuration Guide
Configuring Private VLANs
12-11