Dell Force10 S2410-01-10GE-24P SFTOS Configuration Guide - Page 223

Creating an IP Subnet-based VLAN, Configuring a Private Edge VLAN (PVLAN), Interface Config

Page 223 highlights

Creating an IP Subnet-based VLAN Note: IP Subnet-based VLAN functionality was not tested in SFTOS 2.5.2.0, so it is not supported. As shown in Figure 14-183, use the vlan association subnet ipaddr netmask command in Interface VLAN mode to configure an IP subnet-based VLAN by associating the VLAN with an IP address and subnet mask. Use the show vlan association subnet [ipaddr netmask] command to display the settings. Figure 14-183. Using the vlan association subnet and show vlan association subnet Commands Force10 (Config)#interface vlan 24 Force10 (conf-if-vl-vlan-24)#vlan association subnet 192.168.10.10 255.255.255.0 Force10 (conf-if-vl-vlan-24)#exit Force10 (Config)#show vlan association subnet IP Address IP Mask VLAN ID 192.168.10.10 255.255.255.0 2 Configuring a Private Edge VLAN (PVLAN) Use the Private Edge VLAN feature to prevent selected ports on the switch from forwarding traffic to each other, even if they are on the same VLAN. • Protected ports cannot forward traffic to other protected ports in the same group, even if they have the same VLAN membership. Protected ports can forward traffic to unprotected ports. • Unprotected ports can forward traffic to both protected and unprotected ports. If a port is configured as a protected port, and you then add that port to a Link Aggregation Group (LAG) (also called a port channel), its protected port status becomes operationally disabled, and the port follows its configuration defined for the LAG. However, its protected port configuration remains, so if you remove the port from the LAG, the protected port configuration for that port automatically becomes effective. The commands supporting this feature are: • show interfaces switchport • show switchport protected • switchport protected (Global Config) • switchport protected (Interface Config) For syntax details, see the System Configuration chapter in the SFTOS Command Reference. VLANs | 223

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306

VLANs
|
223
Creating an IP Subnet-based VLAN
As shown in
Figure 14-183
, use the
vlan association subnet
ipaddr netmask
command in Interface VLAN
mode to configure an IP subnet-based VLAN by associating the VLAN with an IP address and subnet
mask. Use the
show vlan association subnet
[
ipaddr netmask
] command to display the settings.
Figure 14-183.
Using the vlan association subnet and show vlan association subnet Commands
Configuring a Private Edge VLAN (PVLAN)
Use the Private Edge VLAN feature to prevent selected ports on the switch from forwarding traffic to each
other, even if they are on the same VLAN.
Protected ports cannot forward traffic to other protected ports in the same group, even if they have the
same VLAN membership. Protected ports can forward traffic to unprotected ports.
Unprotected ports can forward traffic to both protected and unprotected ports.
If a port is configured as a protected port, and you then add that port to a Link Aggregation Group (LAG)
(also called a port channel), its protected port status becomes operationally disabled, and the port follows
its configuration defined for the LAG. However, its protected port configuration remains, so if you remove
the port from the LAG, the protected port configuration for that port automatically becomes effective.
The commands supporting this feature are:
show interfaces switchport
show switchport protected
switchport protected
(Global Config)
switchport protected
(Interface Config)
For syntax details, see the System Configuration chapter in the
SFTOS Command Reference
.
Note:
IP Subnet-based VLAN functionality was not tested in SFTOS 2.5.2.0, so it is not supported.
Force10 (Config)#interface vlan 24
Force10 (conf-if-vl-vlan-24)#vlan association subnet 192.168.10.10 255.255.255.0
Force10 (conf-if-vl-vlan-24)#exit
Force10 (Config)#show vlan association subnet
IP Address
IP Mask
VLAN ID
---------------- ---------------- -------
192.168.10.10
255.255.255.0
2