Configuration Considerations for Isolated or Community PVLAN

The following are some of the configuration considerations to be noted for configuring isolated and community PVLANs.

Isolated VLANs

  • Every isolated VLAN should be in a unique primary VLAN domain.
  • An isolated port can be untagged (implicit-dual-mode) in a non-default VLAN. It need not be an implicit dual-mode port. It can be a purely tagged interface.
    Note: The same is applicable to community and primary VLANs.
  • An isolated port (member of an isolated VLAN) communicates with the promiscuous port if a promiscuous port is configured. If a switch-switch port is configured, the isolated port communicates with the switch-switch port also.
  • An isolated VLAN must be associated with the primary VLAN for traffic to be isolated between isolated VLAN ports and to be switched across primary VLAN ports.
  • An isolated VLAN is associated with only one primary VLAN in entire switched network.
  • A primary VLAN can be associated with only one isolated VLAN. An isolated VLAN can only be mapped to a promiscuous port and a switch-switch link port that belong to the same primary VLAN.

Community VLANs

  • Every community VLAN should be in a unique primary VLAN domain.
  • A port being added to the community VLAN is an implicit dual-mode port.
  • A community VLAN is associated with only one primary VLAN and to the same primary VLAN in the entire switched network.
  • A primary VLAN can be associated with multiple community VLANs.
  • A community VLAN must be associated with the primary VLAN for traffic from the community port to be switched across primary VLAN ports.