Private VLAN Konfigürasyonu

Konu anlatımına burada yer verilmemiştir. Sadece konfigürasyon örneğidir.

Switch#sh run
Building configuration…

Current configuration : 3007 bytes
!
version 12.2
no service pad
service timestamps debug uptime
service timestamps log uptime
no service password-encryption
!
hostname Switch
!
!
no aaa new-model
vtp mode transparent
ip subnet-zero
!
!
!
!
!
!
no file verify auto
spanning-tree mode pvst
spanning-tree extend system-id
!
vlan internal allocation policy ascending
!
vlan 10
private-vlan community
!
vlan 18
!
vlan 20
private-vlan community
!
vlan 30
private-vlan isolated
!
vlan 67
!
vlan 100
private-vlan primary
private-vlan association 10,20,30
!
!
interface FastEthernet0/1
switchport access vlan 18
switchport mode access
switchport port-security maximum 123
switchport port-security
!
interface FastEthernet0/2
!
interface FastEthernet0/3
!
interface FastEthernet0/4
switchport private-vlan host-association 100 10
switchport mode private-vlan host
!
interface FastEthernet0/5
switchport private-vlan host-association 100 10
switchport mode private-vlan host
!
interface FastEthernet0/6
switchport private-vlan host-association 100 10
switchport mode private-vlan host
!
interface FastEthernet0/7
switchport private-vlan host-association 100 20
switchport mode private-vlan host
!
interface FastEthernet0/8
switchport private-vlan host-association 100 20
switchport mode private-vlan host
!
interface FastEthernet0/9
switchport private-vlan host-association 100 20
switchport mode private-vlan host
!
interface FastEthernet0/10
switchport private-vlan mapping 100 10,20,30
switchport mode private-vlan promiscuous
!
interface FastEthernet0/11
switchport private-vlan mapping 100 10,20,30
switchport mode private-vlan promiscuous

!
interface FastEthernet0/22
switchport private-vlan host-association 100 30
switchport mode private-vlan host
!
interface FastEthernet0/23
switchport private-vlan host-association 100 30
switchport mode private-vlan host
!
interface FastEthernet0/24
switchport access vlan 67
switchport private-vlan host-association 100 30
switchport mode private-vlan host
!

end

Switch#

Switch#sh vtp status
VTP Version                     : 2
Configuration Revision          : 0
Maximum VLANs supported locally : 1005
Number of existing VLANs        : 11
VTP Operating Mode              : Transparent
VTP Domain Name                 :
VTP Pruning Mode                : Disabled
VTP V2 Mode                     : Disabled
VTP Traps Generation            : Disabled
MD5 digest                      : 0×44 0×2D 0×9A 0×03 0×5B 0×50 0xA4 0×28
Configuration last modified by 0.0.0.0 at 3-2-93 06:33:46
Switch#
Switch#

Switch#sh vlan private-vlan

Primary Secondary Type              Ports
——- ——— —————– ——————————————
100     10        community         Fa0/4, Fa0/5, Fa0/6, Fa0/10, Fa0/11
100     20        community         Fa0/7, Fa0/8, Fa0/9, Fa0/10, Fa0/11
100     30        isolated          Fa0/10, Fa0/11, Fa0/22, Fa0/23, Fa0/24

Switch#
Switch#

Switch#show interface fastEthernet 0/10 switchport
Name: Fa0/10
Switchport: Enabled
Administrative Mode: private-vlan promiscuous
Operational Mode: private-vlan promiscuous
Administrative Trunking Encapsulation: negotiate
Negotiation of Trunking: Off
Access Mode VLAN: 1 (default)
Trunking Native Mode VLAN: 1 (default)
Administrative Native VLAN tagging: enabled
Voice VLAN: none
Administrative private-vlan host-association: none
Administrative private-vlan mapping: 100 (VLAN0100) 10 (VLAN0010) 20 (VLAN0020) 30 (VLAN0030)
Administrative private-vlan trunk native VLAN: none
Administrative private-vlan trunk Native VLAN tagging: enabled
Administrative private-vlan trunk encapsulation: dot1q
Administrative private-vlan trunk normal VLANs: none
Administrative private-vlan trunk private VLANs: none
Operational private-vlan: none
Trunking VLANs Enabled: ALL
Pruning VLANs Enabled: 2-1001
Capture Mode Disabled
Capture VLANs Allowed: ALL

Protected: false
Unknown unicast blocked: disabled
Unknown multicast blocked: disabled
Appliance trust: none
Switch#

Switch#show interface fastEthernet 0/24 switchport
Name: Fa0/24
Switchport: Enabled
Administrative Mode: private-vlan host
Operational Mode: private-vlan host
Administrative Trunking Encapsulation: negotiate
Operational Trunking Encapsulation: native
Negotiation of Trunking: Off
Access Mode VLAN: 67 (VLAN0067)
Trunking Native Mode VLAN: 1 (default)
Administrative Native VLAN tagging: enabled
Voice VLAN: none
Administrative private-vlan host-association: 100 (VLAN0100) 30 (VLAN0030)
Administrative private-vlan mapping: none
Administrative private-vlan trunk native VLAN: none
Administrative private-vlan trunk Native VLAN tagging: enabled
Administrative private-vlan trunk encapsulation: dot1q
Administrative private-vlan trunk normal VLANs: none
Administrative private-vlan trunk private VLANs: none
Operational private-vlan:
100 (VLAN0100) 30 (VLAN0030)
Trunking VLANs Enabled: ALL
Pruning VLANs Enabled: 2-1001
Capture Mode Disabled
Capture VLANs Allowed: ALL

Protected: false
Unknown unicast blocked: disabled
Unknown multicast blocked: disabled
Appliance trust: none
Switch#

“Private VLAN Konfigürasyonu” için 0 Yorum yapılmış.


  1. Yorum Yapılmamış

Yorum yapın

Yorum yapmak için giriş yapmanız gerekiyor.