Compare cert salaries and plan your next career move
cr33p wrote: I have a question for anyone who knows and understand pvlans. In my company, I have been tasked with creating a pvlan in an existing network with multiple 802.1q VLANs. I have done a lot of reading, but nothing answers this one question: I need to be able to create a pvlan community so that this one vlan is isolated from the rest of the VLANs. The main focus is that I need to ensure I do not disrupt communications on the rest of the network. So how would I go about creating this pvlan if I have a setup similar to the following without disrupting network communications: Catalyst 4006 series Switche CatOS (don't recall which version) Existing VLANs: 16, 17, 18, 21 <-- All can communicate with each other Trunk is on port 1/2 Need to add pvlan 24 <-- No communication with other VLANs, only the DG and other computers in the same vlan. What I think I need to do is to create a primary VLAN, lets say 50. Create pvlan 24 as a community pvlan, Associate PVLAN 24 to vlan 50 and add port 1/2 to pvlan 50 as a promiscious port. Does this sound right, or am I missing something?
dtlokee wrote: I don't think this is an application of private VLANs which are used to prevent hosts on the same VLAN from communicating with other hosts on the same VLAN. You are trying to prevent one VLAN from communicating with another VLAN at a L3 device which is a case for access-lists or VLAN maps. If you create VLAN 24 as a private VLAN (community or otherwise) and the trunk as community,all the hosts can communicate with the router (or other L3 device) then the L3 device will route the packets.
x.x.16.1 x.x.21.1 (access switchs) (x.x.17.1) x.x.18.1 (VLAN's 16,17,18,21,24) x.x.24.1 FW <---- R ----------- L3SW ---------- SW--SW--SW
Compare salaries for top cybersecurity certifications. Free download for TechExams community.