<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Setting up private vlan with our current setup in Switching</title>
    <link>https://community.cisco.com/t5/switching/setting-up-private-vlan-with-our-current-setup/m-p/4311408#M502679</link>
    <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;Its a catch all stanza ( IE: permit ip any any)&lt;/P&gt;</description>
    <pubDate>Mon, 22 Mar 2021 12:48:16 GMT</pubDate>
    <dc:creator>paul driver</dc:creator>
    <dc:date>2021-03-22T12:48:16Z</dc:date>
    <item>
      <title>Setting up private vlan with our current setup</title>
      <link>https://community.cisco.com/t5/switching/setting-up-private-vlan-with-our-current-setup/m-p/4309916#M502533</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;we are managing multiple office which ask for Public IPs (if required by them). we have pool of multiple public IP addresses and we give them the IP from the pool to use them on their router on their end. we have 2 vlans setup on our layer 3 switch, Public vlan 200 and private vlan 50 which has dhcp running. Main gateway connection is coming from ISP switch port to our switch.&lt;BR /&gt;Now my question is: one of the user in public vlan has bunch of public IPs from us and we want to isolate them within the vlan 200 using private vlan.&lt;BR /&gt;where should I start? If I make vlan 200, primary for private vlan, will it create any disconnection in our current setup? I am also remote and my connection is also coming from vlan 200. Can I make changes in current setup of if I have to start from scretch by going onsite?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope I am able to clarify my question, thanks&lt;/P&gt;</description>
      <pubDate>Thu, 18 Mar 2021 19:03:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/setting-up-private-vlan-with-our-current-setup/m-p/4309916#M502533</guid>
      <dc:creator>Talha</dc:creator>
      <dc:date>2021-03-18T19:03:03Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up private vlan with our current setup</title>
      <link>https://community.cisco.com/t5/switching/setting-up-private-vlan-with-our-current-setup/m-p/4310021#M502538</link>
      <description>&lt;P&gt;Hello Talha&lt;BR /&gt;Based on you description and request its not PVLAN you require but a security policy to deny certain pubic hosts from accessing your vlan 50 - Would this be correct or is it that&amp;nbsp; you are actually running PVLAN at this time?&lt;/P&gt;</description>
      <pubDate>Thu, 18 Mar 2021 21:29:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/setting-up-private-vlan-with-our-current-setup/m-p/4310021#M502538</guid>
      <dc:creator>paul driver</dc:creator>
      <dc:date>2021-03-18T21:29:08Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up private vlan with our current setup</title>
      <link>https://community.cisco.com/t5/switching/setting-up-private-vlan-with-our-current-setup/m-p/4310050#M502541</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I just lab tested this and telnetted into a switch, from another switch in the same Vlan. Neither of the configuration parts of the private vlan did disconnect the TELNET session, so doing this remotely should work.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Of course, never forget the old trick of setting a 'reload in' on the remote device, so in case something does go wrong, the switch will reboot and allow you to gain access again, with the original configuration.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Mar 2021 22:27:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/setting-up-private-vlan-with-our-current-setup/m-p/4310050#M502541</guid>
      <dc:creator>Georg Pauwen</dc:creator>
      <dc:date>2021-03-18T22:27:13Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up private vlan with our current setup</title>
      <link>https://community.cisco.com/t5/switching/setting-up-private-vlan-with-our-current-setup/m-p/4310066#M502546</link>
      <description>&lt;P&gt;hi Paul,&lt;/P&gt;&lt;P&gt;Apologies , if I couldn't describe my case properly but actually the case here is a client in vlan 200 wants to isolate himself from other clients in same vlan 200 and I am thinking to configure Pvlan to isolate him. He ran a security vulnerability check and his check is picking up other Public IPs in our public Vlan. Please ignore vlan 50 as I just added it to give you an idea about our network. I am attaching a basic diagram here as well of our network. What are my options? I thought a Pvlan will do the job! but I am not sure where to start in my current scenario.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Mar 2021 23:22:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/setting-up-private-vlan-with-our-current-setup/m-p/4310066#M502546</guid>
      <dc:creator>Talha</dc:creator>
      <dc:date>2021-03-18T23:22:39Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up private vlan with our current setup</title>
      <link>https://community.cisco.com/t5/switching/setting-up-private-vlan-with-our-current-setup/m-p/4310067#M502547</link>
      <description>&lt;P&gt;that's a good check, thanks&lt;/P&gt;&lt;P&gt;doesnt "reload in" is by default present.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Mar 2021 23:20:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/setting-up-private-vlan-with-our-current-setup/m-p/4310067#M502547</guid>
      <dc:creator>Talha</dc:creator>
      <dc:date>2021-03-18T23:20:51Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up private vlan with our current setup</title>
      <link>https://community.cisco.com/t5/switching/setting-up-private-vlan-with-our-current-setup/m-p/4310092#M502550</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;no, it is not in the configuration by default, you need to add that manually when working on the switch remotely...&lt;/P&gt;</description>
      <pubDate>Fri, 19 Mar 2021 00:15:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/setting-up-private-vlan-with-our-current-setup/m-p/4310092#M502550</guid>
      <dc:creator>Georg Pauwen</dc:creator>
      <dc:date>2021-03-19T00:15:00Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up private vlan with our current setup</title>
      <link>https://community.cisco.com/t5/switching/setting-up-private-vlan-with-our-current-setup/m-p/4310392#M502585</link>
      <description>&lt;P&gt;Ok I see, I didn't know that option. awesome&lt;/P&gt;</description>
      <pubDate>Fri, 19 Mar 2021 12:59:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/setting-up-private-vlan-with-our-current-setup/m-p/4310392#M502585</guid>
      <dc:creator>Talha</dc:creator>
      <dc:date>2021-03-19T12:59:54Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up private vlan with our current setup</title>
      <link>https://community.cisco.com/t5/switching/setting-up-private-vlan-with-our-current-setup/m-p/4311159#M502663</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/465372"&gt;@Talha&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;case here is a client in vlan 200 wants to isolate himself from other clients in same vlan 200&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Try the following vlan access map example:&lt;EM&gt;&lt;BR /&gt;&lt;BR /&gt;access-list 101 permit ip host 200.0.0.1 200.0.0.0 0.0.0.255&lt;BR /&gt;&lt;/EM&gt;&lt;EM&gt;access-list 101 permit ip 200.0.0.0 0.0.0.255&amp;nbsp; host 200.0.0.1&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;EM&gt;vlan access-map Vl200_host&lt;BR /&gt;&lt;/EM&gt;&lt;EM&gt;match ip address 101&lt;BR /&gt;&lt;/EM&gt;&lt;EM&gt;action drop&lt;BR /&gt;&lt;/EM&gt;&lt;EM&gt;vlan access-map Vl200_host 99&lt;BR /&gt;&lt;BR /&gt;vlan filter Vl200_host vlan-list 200&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 21 Mar 2021 23:48:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/setting-up-private-vlan-with-our-current-setup/m-p/4311159#M502663</guid>
      <dc:creator>paul driver</dc:creator>
      <dc:date>2021-03-21T23:48:51Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up private vlan with our current setup</title>
      <link>https://community.cisco.com/t5/switching/setting-up-private-vlan-with-our-current-setup/m-p/4311326#M502672</link>
      <description>Hi Paul,&lt;BR /&gt;Thanks for the response&lt;BR /&gt;If he has ip 207.x.x.89 to 207.x.x.93 in a 16 ip pool then how will this vlan filter look like? Should i then add each ip in seperate line.&lt;BR /&gt;</description>
      <pubDate>Mon, 22 Mar 2021 09:51:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/setting-up-private-vlan-with-our-current-setup/m-p/4311326#M502672</guid>
      <dc:creator>Talha</dc:creator>
      <dc:date>2021-03-22T09:51:57Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up private vlan with our current setup</title>
      <link>https://community.cisco.com/t5/switching/setting-up-private-vlan-with-our-current-setup/m-p/4311355#M502674</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;Just amend the acl to accomodate.( please make sure the acl number is not already being used!)&lt;BR /&gt;Example:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;access-list 101 permit ip host 207.x.x.89 207.0.0.0 0.0.255.255&lt;BR /&gt;&lt;/EM&gt;&lt;EM&gt;access-list 101 permit ip 207.x.x.0 0.0.255.255&amp;nbsp; host 207.x.x.89&lt;BR /&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;EM&gt;access-list 101 permit ip host 207.x.x.90 207.0.0.0 0.0.255.255&lt;BR /&gt;access-list 101 permit ip 207.x.x.0 0.0.255.255&amp;nbsp; host 207.x.x.90&lt;BR /&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;etc..&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Mar 2021 10:52:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/setting-up-private-vlan-with-our-current-setup/m-p/4311355#M502674</guid>
      <dc:creator>paul driver</dc:creator>
      <dc:date>2021-03-22T10:52:41Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up private vlan with our current setup</title>
      <link>https://community.cisco.com/t5/switching/setting-up-private-vlan-with-our-current-setup/m-p/4311398#M502678</link>
      <description>&lt;P&gt;sure thanks, let me give it a try with Reload at command in case.&lt;BR /&gt;And can you tell what is 99 here in this line below that you wrote earlier? Also in the wild card mask is different from earlier reply, is it deliberate?&lt;BR /&gt;&lt;BR /&gt;vlan access-map Vl200_host 99&lt;/P&gt;</description>
      <pubDate>Mon, 22 Mar 2021 12:48:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/setting-up-private-vlan-with-our-current-setup/m-p/4311398#M502678</guid>
      <dc:creator>Talha</dc:creator>
      <dc:date>2021-03-22T12:48:01Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up private vlan with our current setup</title>
      <link>https://community.cisco.com/t5/switching/setting-up-private-vlan-with-our-current-setup/m-p/4311408#M502679</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;Its a catch all stanza ( IE: permit ip any any)&lt;/P&gt;</description>
      <pubDate>Mon, 22 Mar 2021 12:48:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/setting-up-private-vlan-with-our-current-setup/m-p/4311408#M502679</guid>
      <dc:creator>paul driver</dc:creator>
      <dc:date>2021-03-22T12:48:16Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up private vlan with our current setup</title>
      <link>https://community.cisco.com/t5/switching/setting-up-private-vlan-with-our-current-setup/m-p/4311439#M502680</link>
      <description>&lt;P&gt;I see ok.&lt;/P&gt;&lt;P&gt;Can you please also confirm the wild card mask in the ACLs, should it be 0.0.0.255 or 0.0.255.255? thanks&lt;/P&gt;</description>
      <pubDate>Mon, 22 Mar 2021 13:30:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/setting-up-private-vlan-with-our-current-setup/m-p/4311439#M502680</guid>
      <dc:creator>Talha</dc:creator>
      <dc:date>2021-03-22T13:30:34Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up private vlan with our current setup</title>
      <link>https://community.cisco.com/t5/switching/setting-up-private-vlan-with-our-current-setup/m-p/4311441#M502681</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/465372"&gt;@Talha&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;207.x.x.89 to 207.x.x.93 in a &lt;STRONG&gt;16 ip poo&lt;/STRONG&gt;l then how will this vlan filter look like? Should i then add each ip in &lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Can you please also confirm the wild card mask in the ACLs, should it be 0.0.0.255 or 0.0.255.255? thanks&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;EM&gt;207.x.x.0/16&amp;nbsp; = 207.x.x.0 0.0.255.255&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Mar 2021 13:34:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/setting-up-private-vlan-with-our-current-setup/m-p/4311441#M502681</guid>
      <dc:creator>paul driver</dc:creator>
      <dc:date>2021-03-22T13:34:36Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up private vlan with our current setup</title>
      <link>https://community.cisco.com/t5/switching/setting-up-private-vlan-with-our-current-setup/m-p/4311450#M502682</link>
      <description>&lt;P&gt;Sorry just verified, its a pool of 32 ip address with subnet of 255.255.255.224&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Mar 2021 13:40:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/setting-up-private-vlan-with-our-current-setup/m-p/4311450#M502682</guid>
      <dc:creator>Talha</dc:creator>
      <dc:date>2021-03-22T13:40:03Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up private vlan with our current setup</title>
      <link>https://community.cisco.com/t5/switching/setting-up-private-vlan-with-our-current-setup/m-p/4311454#M502683</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;Okay then the acl will need to be changed to accomodate a /27 subnet and which ever range those hosts reside in?&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;207.x.x.&lt;STRONG&gt;0&lt;/STRONG&gt;/27&amp;nbsp; = 207.x.x.&lt;STRONG&gt;0&lt;/STRONG&gt; 0.0.0.31&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;207.x.x.&lt;STRONG&gt;32&lt;/STRONG&gt;/27&amp;nbsp; = 207.x.x.&lt;STRONG&gt;32&lt;/STRONG&gt; 0.0.0.31&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;207.x.x.&lt;STRONG&gt;64&lt;/STRONG&gt;/27&amp;nbsp; = 207.x.x.&lt;STRONG&gt;64&lt;/STRONG&gt; 0.0.0.31&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;207.x.x.&lt;STRONG&gt;96&lt;/STRONG&gt;/27&amp;nbsp; = 207.x.x.&lt;STRONG&gt;96&lt;/STRONG&gt; 0.0.0.31&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;etc...&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Mar 2021 13:47:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/setting-up-private-vlan-with-our-current-setup/m-p/4311454#M502683</guid>
      <dc:creator>paul driver</dc:creator>
      <dc:date>2021-03-22T13:47:32Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up private vlan with our current setup</title>
      <link>https://community.cisco.com/t5/switching/setting-up-private-vlan-with-our-current-setup/m-p/4311458#M502685</link>
      <description>&lt;P&gt;thanks alot Paul, will try it and follow up &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Mar 2021 13:50:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/setting-up-private-vlan-with-our-current-setup/m-p/4311458#M502685</guid>
      <dc:creator>Talha</dc:creator>
      <dc:date>2021-03-22T13:50:46Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up private vlan with our current setup</title>
      <link>https://community.cisco.com/t5/switching/setting-up-private-vlan-with-our-current-setup/m-p/4311465#M502686</link>
      <description>&lt;P&gt;May be I am over cautious , sorry to bug you here &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;do I have to explicitly allow gateway as it is part of same pool. What a I understood that we are denying the traffic from his IPs to all vlan 200 network? lets say if gateway is .65, wouldn't it block his internet access?&lt;/P&gt;</description>
      <pubDate>Mon, 22 Mar 2021 13:57:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/setting-up-private-vlan-with-our-current-setup/m-p/4311465#M502686</guid>
      <dc:creator>Talha</dc:creator>
      <dc:date>2021-03-22T13:57:51Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up private vlan with our current setup</title>
      <link>https://community.cisco.com/t5/switching/setting-up-private-vlan-with-our-current-setup/m-p/4311474#M502687</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;No just specify the end host ip addressing to from the subent thats it, no need to specify any gateway address just be specific on the host ip addresses&lt;/P&gt;</description>
      <pubDate>Mon, 22 Mar 2021 14:09:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/setting-up-private-vlan-with-our-current-setup/m-p/4311474#M502687</guid>
      <dc:creator>paul driver</dc:creator>
      <dc:date>2021-03-22T14:09:24Z</dc:date>
    </item>
  </channel>
</rss>

