私用VLAN的作用:解决VLAN个数限制、相同VLAN之间不能互访
Secondary VLANs (辅助私用VLAN):ISOLATED VLAN(孤立VLAN)、Community VLAN(团体VLAN)
Secondary VLANs之间是不能互访的,ISOLATED VLAN不可互访,Community VLAN可互访私用VLAN的三种端口类型:
Promiscuous杂合端口:主VLAN的一部分,可以与所有VLAN的端口通信。Isolated孤立端口:和同一个pVlan中所有端口相隔离,但是可以和杂合端口通信。(据说在现实场景中比较常用Isolated端口)
Community团体端口:同一个团体端口之间可以互相通信,也可以和杂合端口通信,但是和其他团体的接口是二层隔离的。
模拟组网:
基本配置:
SW1上配置:
VTP mode transparent/offvlan 20
private-vlan primary (主VLAN)
vlan 501
private-vlan community (联盟VLAN)
vlan 502
private-vlan isolated (隔离VLAN)
vlan 20
private-vlan association 501,502
SW1连接R1的接口配置:
switchport mode private-vlan promiscuous (说明端口是混杂端口)
switchport private-vlan mapping 20 501,502 (20是主VLAN, 501,502是从VLAN)作用是说明VLAN20可以和VLAN501,502通信
SW1连接R2和SW2的2个接口配置:
switchport mode private-vlan host (host相当于是接主机)
switchport private-vlan host-assocaition 20 501 (20是主VLAN,501是接口连接的VLAN)
SW1连接SW3和SW4的2个接口配置:
switchport mode private-vlan host
switchport private-vlan host-assocaition 20 502
查看配置:
show vlan private-vlan
show int f 0/1 switchport