cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1052
Views
0
Helpful
1
Replies

Private Vlan and Switchport Protected

chan-kuen.hui
Level 1
Level 1

Dear All,

My core switch is 4500 which support Private Vlan. However, I have several closet switch (2950) which only support Switchport Protected. 4500 and each 2950 are connected with trunk using fiber.

How can I config PC at 2950_Switch1 cannot communicate to PC at 2950_Switch2 (all fastethernet port on both 2950 are at the same vlan and same subnet)?

Thanks.

C.K.

1 Reply 1

amit-singh
Level 8
Level 8

Hi C.k.,

I believe you can use switchport protected feature along with port blocking feature to accomplish this. First have your switch ports configured as protected ports on which you dont want the traffic to flow and then configure those ports to deny unknown unicast and multicast using the " port-blocking feature ".

Try that and let us know.

http://www.cisco.com/univercd/cc/td/doc/product/lan/cat2950/12120ea2/2950scg/swtrafc.htm#wp1174968

HTH,

-amit singh