10-25-2022 03:05 PM - edited 10-25-2022 03:46 PM
Hi,
In our network design, our PCs are connected each to a port in trunk mode on the switch because they belong to multiple vlans (traffic isolation). The PCs tag the data themselves.
Now we want to introduce pvlans to isolate PCs. We know that it is possible to do this with isolated pvlan on the PCs ports and promiscuous ports on the server ports; this works well with one isolated pvlan/primary pvlan.
But is it possible to configure multiple isolated pvlans on a single port?
For example on Cisco 4500 serie, I see Private VLAN Trunk Port which carries multiple secondary (isolated only) and non-PVLANs. Does it do the job? Otherwise how to do this on a Cisco switch?
Thanks for your help.
Example:
Expected result:
10-26-2022 07:00 AM
AFAIK this is not possible
using private VLAN's packets are sent or received untagged on different VLANs hence the isolation
NB! this is a vlan PAIR
-> not suitable for trunk ports
the trunk port you mention in your setup is the place where upstream and downstream traffic for a private vlan pair come together
10-26-2022 02:59 PM
Thank you Pieterh for your reply.
This means that it is not possible to have multiple primary vlans on a single port. So sad as it is possible to have the expected behaviour (multiple vlans on a trunk port, isolation between ports) on a single switch with the "switchport protected" command.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide