Private vlans, Private vlan ports – Juniper Networks EX2500 User Manual

Page 45

Advertising
background image

Private VLANs

„

31

Chapter 2: VLANs

Private VLANs

Private VLANs provide Layer 2 isolation between the ports within the same
broadcast domain. Private VLANs can control traffic within a VLAN domain, and
provide port-based security for host servers.

Use private VLANs to partition a VLAN domain into sub-domains. Each sub-domain
is comprised of one primary VLAN and one or more secondary VLANs, as follows:

„

Primary VLAN—Carries unidirectional traffic downstream from promiscuous
ports. Each private VLAN configuration has only one primary VLAN. All ports in
the private VLAN are members of the primary VLAN.

„

Secondary VLAN—Secondary VLANs are internal to a private VLAN domain,
and are defined as follows:

„

Isolated VLAN—Carries unidirectional traffic upstream from the host
servers toward ports in the primary VLAN and the gateway. Each private
VLAN configuration can contain only one isolated VLAN.

„

Community VLAN—Carries upstream traffic from ports in the community
VLAN to other ports in the same community, and to ports in the primary
VLAN and the gateway. Each private VLAN configuration can contain
multiple community VLANs.

After you define the primary VLAN and one or more secondary VLANs, you map
the secondary VLAN(s) to the primary VLAN.

Private VLAN Ports

Private VLAN ports are defined as follows:

„

Promiscuous—A promiscuous port is a port that belongs to the primary VLAN.
The promiscuous port can communicate with all the interfaces, including ports
in the secondary VLANs (isolated VLAN and community VLANs). Each
promiscuous port can belong to only one private VLAN.

„

Isolated—An isolated port is a host port that belongs to an isolated VLAN. Each
isolated port has complete Layer 2 separation from other ports within the same
private VLAN (including other isolated ports), except for the promiscuous ports.

„

Traffic sent to an isolated port is blocked by the private VLAN, except the
traffic from promiscuous ports.

„

Traffic received from an isolated port is forwarded only to promiscuous
ports.

„

Community—A community port is a host port that belongs to a community
VLAN. Community ports can communicate with other ports in the same
community VLAN, and with promiscuous ports. These interfaces are isolated at
Layer 2 from all other interfaces in other communities and from isolated ports
within the private VLAN.

Advertising