CLI Example for a General PVLAN Network

To configure the PVLANs shown in PVLAN Used to Secure Communication Between a Workstation and Servers, enter the following commands.

  1. Create a VLAN.
    device(config)# vlan 901
  2. Add the untagged ethernet ports to this VLAN.
    device(config-vlan-901)# untagged ethernet 1/3/5 to 1/3/6
  3. Configure the PVLAN as community type.
    device(config-vlan-901)# pvlan type community
    device(config-vlan-901)# exit
    
  4. Create a VLAN 902 and add the untagged ethernet ports.
    device(config)# vlan 902
    device(config-vlan-902)# untagged ethernet 1/3/9 to 1/3/10
  5. Configure the VLAN 902 as isolated VLAN in a PVLAN.
    device(config-vlan-902)# pvlan type isolated
    device(config-vlan-902)# exit
    
  6. Create another VLAN and add the untagged ethernet ports.
    device(config)# vlan 903
    device(config-vlan-903)# untagged ethernet 1/3/5 to 1/3/6
  7. Configure the PVLAN as community type.
    device(config-vlan-903)# pvlan type community
    device(config-vlan-903)# exit
    
    
  8. Create a new VLAN and configure as primary PVLAN type. Map the isolated VLAN and community VLAN to the primary VLAN as promiscuous ports.
    device(config)# vlan 7
    device(config-vlan-7)# untagged ethernet 1/3/2
    device(config-vlan-7)# pvlan type primary
    device(config-vlan-7)# pvlan mapping 901 ethernet 1/3/2
    device(config-vlan-7)# pvlan mapping 902 ethernet 1/3/2
    device(config-vlan-7)# pvlan mapping 903 ethernet 1/3/2