Configuration Notes for PVLANs and Standard VLANs

  • PVLANs are supported on untagged ports on all RUCKUS ICX platforms.
  • Normally, in any port-based VLAN, the device floods unknown unicast, unregistered multicast, and broadcast packets in hardware, although selective packets, such as IGMP, may be sent only to the CPU for analysis, based on the IGMP snooping configuration. When protocol is enabled, or if PVLAN mappings are enabled, the RUCKUS ICX device will flood unknown unicast and unregistered multicast packets in software. The flooding of broadcast or unknown unicast from the community or isolated VLANs to other secondary VLANs will be governed by the PVLAN forwarding rules. The switching is done in hardware and thus the CPU does not enforce packet restrictions.
  • RUCKUS ICX devices forward broadcast, unregistered-multicast, and unknown unicast traffic in hardware if PVLAN mappings are enabled. When PVLAN mappings are enabled, multiple MAC entries for the same MAC do not appear in the MAC table, instead all the MAC entries are learned in the primary VLAN.
  • To configure a PVLAN, configure each of the component VLANs (isolated, community, and primary) as a separate port-based VLAN:
    • Use standard VLAN configuration commands to create the VLAN and add ports.
    • Identify the PVLAN type (isolated, community, or primary).
    • For the primary VLAN, map the other secondary PVLANs to the ports in the primary VLAN.
  • A primary VLAN can have multiple ports. All these ports are active, but the ports that will be used depends on the PVLAN mappings. Also, secondary VLANs (isolated and community VLANs) can be mapped to more than one primary VLAN port.
  • You can configure PVLANs and implicit dual-mode VLAN ports on the same device. However, the VLAN ports, other than those which are implicit dual-mode in system default VLAN, can be member ports in a PVLAN domain.
  • When an implicit dual-mode port in system default VLAN is added to a private VLAN, that port is removed from default VLAN.
  • VLAN identifiers configured as part of a PVLAN (primary, isolated, or community) should be consistent across the switched network. The same VLAN identifiers cannot be configured as a normal VLAN or a part of any other PVLAN.
  • Implicit dual-mode ports which are untagged to non-default VLAN are supported in a private VLAN domain. However, since ISL ports can only be tagged ports, they cannot be enabled on implicit dual-mode ports.
  • Member ports in a private VLAN domain can be extended to other domains as long as they belong to the same private VLAN type. Refer to Possible Configurations Allowed in a PVLAN to know more about allowed configurations in a PVLAN. All user configurations beyond the scope of the table will not be allowed.
  • PVLAN ports cannot be added to regular VLANs. You must configure the regular VLAN as PVLAN before adding the ports.
  • A regular VLAN cannot be configured as PVLAN if the ports of the regular VLAN are part of any other regular VLAN. In such a scenario, you must configure both regular VLANs as PVLANs.
  • PVST, when needed in PVLANs, should be enabled on all (primary and secondary) private VLANs across switches.
  • Port MAC security is not supported on ports in a private VLAN domain.

PVLAN Support Matrix

Platform Forwarding Type Tagged Port Untagged Port ISL Port Multiple Promiscuous Port
ICX 7150 Hardware Yes Yes Yes Yes
ICX 7250 Hardware Yes Yes Yes Yes
ICX 7450 Hardware Yes Yes Yes Yes
ICX 7650 Hardware Yes Yes Yes Yes
ICX 7850 Hardware Yes Yes Yes Yes