Switchport ingress-filtering, Switchport ingress, Filtering – Microsens MS453490M Management Guide User Manual

Page 791

Advertising
background image

C

HAPTER

34

| VLAN Commands

Configuring VLAN Interfaces

– 791 –

If a trunk has switchport mode set to trunk (i.e., 1Q Trunk), then you

can only assign an interface to VLAN groups as a tagged member.

Frames are always tagged within the switch. The tagged/untagged

parameter used when adding a VLAN to an interface tells the switch

whether to keep or remove the tag from a frame on egress.

If none of the intermediate network devices nor the host at the other

end of the connection supports VLANs, the interface should be added to

these VLANs as an untagged member. Otherwise, it is only necessary to

add at most one VLAN as untagged, and this should correspond to the

native VLAN for the interface.

If a VLAN on the forbidden list for an interface is manually added to

that interface, the VLAN is automatically removed from the forbidden

list for that interface.

E

XAMPLE

The following example shows how to add VLANs 1, 2, 5 and 6 to the

allowed list as tagged VLANs for port 1:

Console(config)#interface ethernet 1/1

Console(config-if)#switchport allowed vlan add 1,2,5,6 tagged

Console(config-if)#

switchport ingress-

filtering

This command enables ingress filtering for an interface. Use the no form to

restore the default.

S

YNTAX

[no] switchport ingress-filtering

D

EFAULT

S

ETTING

Disabled

C

OMMAND

M

ODE

Interface Configuration (Ethernet, Port Channel)

C

OMMAND

U

SAGE

Ingress filtering only affects tagged frames.

If ingress filtering is disabled and a port receives frames tagged for

VLANs for which it is not a member, these frames will be flooded to all

other ports (except for those VLANs explicitly forbidden on this port).

If ingress filtering is enabled and a port receives frames tagged for

VLANs for which it is not a member, these frames will be discarded.

Ingress filtering does not affect VLAN independent BPDU frames, such

as GVRP or STA. However, they do affect VLAN dependent BPDU

frames, such as GMRP.

Advertising