Networking, Security & Cloud Knowledge

Sunday, June 26, 2011

019- Private Vlan

Step 1: Setting device to VTP TRANSPARENT mode

Switch(config)# vtp mode transparent

Step 2: Creating VLANs [Secondary vlans / Private Vlan]
vlan 101 = isolated vlan
vlan 102 = community vlan

Primary vlans (Secondary VLANs are associate to primary VLANs)
vlan 100 = primary vlan

Switch(config)# vlan 101
Switch(config-vlan)# private-vlan isolated

Switch(config)# vlan 102
Switch(config-vlan)# private-vlan community

Switch(config)# vlan 100
Switch(config-vlan)# private-vlan primary
Switch(config-vlan)# private-vlan association 101,102


Step 3: Assigning port to vlan
Port Fa0/1 = Promiscuous ( For Router / Firewalls)
Port Fa0/3, Fa0/5, Fa0/6 = Host Ports ( For Hosts)

Switch(config)# interface f0/1
Switch(config-if)# switchport mode private-vlan promiscuous
Switch(config-if)# switchport private-vlan mapping 100 add 101 102

Our two server ports will be configured in host mode:
Switch(config)# interface f0/3
Switch(config-if)# switchport mode private-vlan host
Switch(config-if)# switchport private-vlan host-association 100 101

Switch(config-if)# interface f0/5
Switch(config-if)# switchport mode private-vlan host
Switch(config-if)# switchport private-vlan host-association 100 102

Switch(config-if)# interface f0/6
Switch(config-if)# switchport mode private-vlan host
Switch(config-if)# switchport private-vlan host-association 100 102

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.