No video

Private VLAN Lab

PRIVATE VLAN:
• Private VLANs (PVLANs) can be implemented to prevent hosts within a VLAN from communicating directly.
• In order to increase security by separating devices into many small VLANs conflicts with the design goal of conserving the use of the available IP subnets. The Cisco private VLAN feature addresses this issue.
• Private VLANs allow a switch to separate ports as if they were on different VLANs, while consuming only a single subnet.
• A common place to implement private VLANs is in the service provider (SP).
• The SP can install a single router and a single switch. Then, the SP attaches devices from multiple customers to the switch. Private VLANs then allow the SP to use only a single subnet for the whole building, separating different customers' switch ports so that they cannot communicate directly, while supporting all customers with a single router and switch.
Primary (regular) VLANs are associated with secondary (private) VLANs.
A secondary VLAN can be one of two types:
• Isolated - Hosts associated with the VLAN can only reach the primary VLAN.
• Community - Hosts can communicate with the primary VLAN and other hosts within the secondary VLAN, but not with other secondary VLANs.
Note: PVLAN information is not communicated by VTP.
PVLAN ports are configured to operate in one of two modes:
• Promiscuous - Port attaches to a router, firewall, etc; can communicate with all hosts ( including isolated and community ports)
• Host - Can only communicate with a promiscuous port, or ports within the same community PVLAN

Пікірлер: 31

  • @Rickfromva
    @Rickfromva9 жыл бұрын

    Thank you for this Video. I am use to working with routing and could not get my head around private VLANS and why I would use them. Your Video really helped and will go along way to helping to pass the switching part of the CCNP test. Thank you again!

  • @srikanthsanthanam9266
    @srikanthsanthanam92667 жыл бұрын

    Excellent work.able to understand easily.

  • @cbaxtermusic
    @cbaxtermusic10 жыл бұрын

    awesome video, one of the things i was getting caught up on was the IP address association to the Layer-2 subboundaries, in regards to broadcast. most examples ive seen would configure the primary VLAN on a swtich acting as the ISP with an SVI with subnet of /24, then the associated community vlans as multiple /28's for the customer networks, the first thing that comes to mind is that you have now trapped your /28's with in that routing domain due to the fact it will not have a valid default gateway, due to the /24 of that subnet being on the primary VLAN, the only way i seeing those configus working is if you use a secondary IP address on the primary vlan thus making you have to subnet and kinda of defeating the purpose of private vlans i think your approach is more practical , correct me if i am wrong from my above statements, but if you use private-vlans as a L2 service from the ISP perspective, you can statically assign what would be an WAN address to the customer essentially a host address within your subnet, then configure a promiscuous port as the GW uplink. once again keep em coming great vid

  • @aquadir2830
    @aquadir28305 жыл бұрын

    You're excellent. I clear my doubt today. Thank you sir.

  • @thangarajk546

    @thangarajk546

    5 жыл бұрын

    Tell me onething , How the switch will act as a router?.

  • @mh63111

    @mh63111

    4 жыл бұрын

    @@thangarajk546 use the below configuration to do that: conf t hostname SW2 vlan 10 int e0/0 switchport mode access switchport access vlan 10 int vlan 10 ip add 192.168.1.4 255.255.255.0 no shut

  • @fakirmohideen1837
    @fakirmohideen18376 жыл бұрын

    Very useful video. Thank NOA.

  • @anilisd241
    @anilisd2419 жыл бұрын

    Thank you for this Video. I am use to working with routing and could not get my head around private VLANS and why I would use them.

  • @r.a.rashed4450
    @r.a.rashed44508 жыл бұрын

    Thank you for this Video. it is helpful.

  • @MrTechnomantra
    @MrTechnomantra3 жыл бұрын

    perfect, thanks

  • @shaikarshad9670
    @shaikarshad96708 жыл бұрын

    super b..teaching..

  • @MrSledge121
    @MrSledge1217 жыл бұрын

    Good work.

  • @emmiie5101
    @emmiie51013 жыл бұрын

    THANK YOUUUUUU!!!

  • @priyanktrivedi5673
    @priyanktrivedi56733 жыл бұрын

    Hi, My query is one L3 connected to saveral location within organisation and same subnet. Private concept is devide sub vlan, but can we assign DHCP after subnetting the same subnet from L3 to other L2 switches...

  • @cdhumal026
    @cdhumal0268 жыл бұрын

    nicely explained !!!!! :)

  • @joswill23
    @joswill233 жыл бұрын

    Hi guys please help, private-vlan command not showing. What should i do ?

  • @ammarabbasi
    @ammarabbasi2 жыл бұрын

    in case it helps someone: ports while in vlan1 ( default VLAN ) do not work in promiscuous mode. private VLAN type will show non-operational.

  • @rasheedmalik6594
    @rasheedmalik65943 жыл бұрын

    why cant we use VACLs to permit or deny traffic from/to ports? Also is this concept of PVLANs cisco proprietary?

  • @AashishSapkota
    @AashishSapkota6 жыл бұрын

    i am not getting the private vlan command feature in cisco packet tracer.Does private vlan commands work in cisco packet tracer or GNS will be required ?please help

  • @jknslpat1
    @jknslpat12 жыл бұрын

    In Packet Tracer 7.3.1 as well as 8.0.0 private-vlan command is not working.. Pls suggest how to do practice on packet tracer for private-vlan.

  • @zinouhadj8474
    @zinouhadj84743 жыл бұрын

    If i was 2 interfaces that Will be portchannel to firewall layer 3 how can configure promoscuos port on that interfaces

  • @vishnudas1671
    @vishnudas16713 жыл бұрын

    Sir because of the sub title cant able to note down the class poroperly

  • @Prashanthkadem
    @Prashanthkadem8 жыл бұрын

    it would be great if you make a video on how to make switches work in gns3.. tq

  • @olliemaster2442
    @olliemaster24424 жыл бұрын

    what does the configuration on the router side look like?

  • @aksel9392
    @aksel93924 жыл бұрын

    thank you for the viseo,and if you share the config file with us i ll be grateful

  • @surya2347
    @surya23476 жыл бұрын

    how to download 3560 switch plz reply

  • @Prashanthkadem
    @Prashanthkadem8 жыл бұрын

    how are you working on switches in gns3.... I have tried using secure CRT... but not able to access them.

  • @BharathDragon

    @BharathDragon

    6 жыл бұрын

    use VMware workstation

  • @thangarajk6898
    @thangarajk68985 жыл бұрын

    How can I assign the IP address to Switch?

  • @mh63111

    @mh63111

    4 жыл бұрын

    conf t hostname SW3 vlan 10 int e0/0 switchport mode access switchport access vlan 10 int vlan 10 ip add 192.168.1.6 255.255.255.0 no shut

  • @secureict3407

    @secureict3407

    4 жыл бұрын

    Better do it in native - VLAN1, if you are planing to keep as flat network, as long as all port belong to VLAN1 # conf t # interface vlan 1 # ip address 192.168.1.1 255.255.255.0 # no shutdown # exit # wr