vlan
vlan vlan-id [ to
vlan-id
| [ vlan-id to vlan-id |
vlan-id
] …
]
[ name string ]
[ by port ]no vlan vlan-id [
to vlan-id | [
vlan-id to vlan-id
| vlan-id ] … ]
[ name string
] [ by port ]The default VLAN is 1. Maximum allowed discrete or set of VLAN(s) is 1024.
Global configuration mode
You can configure up to 4061 port-based VLANs on a device. Each port-based VLAN can contain either tagged or untagged ports. A port cannot be a member of more than one port-based VLAN unless the port is tagged.
The following example creates a port-based VLAN.
device# configure terminal device(config)# vlan 222 by port
The following example shows the port-based VLAN configuration.
device# configure terminal device(config)# vlan 10 name IP_VLAN by port device(config-vlan-10)# untagged ethernet 1/1/1 to 1/1/6 added untagged port ethe 1/1/1 to 1/1/6 to port-vlan 10.
The following example creates continuous and discontinuous VLANs.
device# configure terminal device(config)# vlan 2 to 7 20 25 device(config-mvlan-2*25)#
The following example creates continuous VLANs.
device# configure terminal device(config)# vlan 2 to 7 device(config-mvlan-2-7)#
The following example creates discontinuous VLANs.
device# configure terminal device(config)# vlan 2 4 7 device(config-mvlan-2*7)#
The following example binds an IPv4 ACL to members of a VLAN.
device(config)# vlan 6 device(config-vlan6)# ip access-group acl1 in ethernet 1/1/3 ethernet 3/1/2 lag 1
The following example binds several ACLs, including IPv6, IPv4, and MAC ACLs, to VLAN 555.
device# configure terminal device(config)# vlan 555 by port device(config-vlan-555)# tagged ethe 1/2/2 lag 10 device(config-vlan-555)# interface ve 555 device(config-vlan-555)# ipv6 access-group scale25 in device(config-vlan-555)# ipv6 access-group scale15 out device(config-vlan-555)# mac access-group mac_acl1 in device(config-vlan-555)# ip access-group 123 in device(config-vlan-555)# ip access-group 134 out device(config-vlan-555)# exit device(config)#
The following example applies IPv6, IPv4, and MAC ACLs to tagged Ethernet port 1/2/2 specifically within LAG 10 and enables logging of traffic that matches any statement within the applied ACLs that contains the log keyword.
device# configure terminal device(config)# vlan 558 by port device(config-vlan-558)# tagged ethe 1/2/2 lag 10 device(config-vlan-558)# ipv6 access-group scale12 in lag 10 logging enable device(config-vlan-558)# mac access-group mac_acl in lag 10 device(config-vlan-558)# ip access-group 134 in lag 10 logging enable