HP 6120XG HP ProCurve Series 6120 Blade Switches Advanced Traffic Management G - Page 69

The Secure Management VLAN, Primary VLAN. To display the current Primary VLAN, use the CLI

Page 69 highlights

Static Virtual LANs (VLANs) Special VLAN Types ■ Any ports not specifically assigned to another VLAN will remain assigned to the Default VLAN, regardless of whether it is the Primary VLAN. Candidates for Primary VLAN include any static, port-based VLAN currently configured on the switch. (Protocol-Based VLANs and dynamic-GVRPlearned-VLANs that have not been converted to a static VLAN cannot be the Primary VLAN.) To display the current Primary VLAN, use the CLI show vlan command. Note If you configure a non-default VLAN as the Primary VLAN, you cannot delete that VLAN unless you first select a different VLAN to serve as primary. If you manually configure a gateway on the switch, it ignores any gateway address received via DHCP or Bootp. To change the Primary VLAN configuration, refer to "Changing the Primary VLAN" on page 2-34. The Secure Management VLAN Configuring a secure Management VLAN creates an isolated network for managing the ProCurve switches that support this feature. If you configure a secure Management VLAN, access to the VLAN and to the switch's management functions (Menu, CLI, and web browser interface) is available only through ports configured as members. ■ Multiple ports on the switch can belong to the Management VLAN. This allows connections for multiple management stations you want to have access to the Management VLAN, while at the same time allowing Management VLAN links between switches configured for the same Management VLAN. ■ Only traffic from the Management VLAN can manage the switch, which means that only the workstations and PCs connected to ports belonging to the Management VLAN can manage and reconfigure the switch. Figure 2-29 illustrates use of the Management VLAN feature to support management access by a group of management workstations. 2-46

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222

2-46
Static Virtual LANs (VLANs)
Special VLAN Types
Any ports not specifically assigned to another VLAN will remain assigned
to the Default VLAN, regardless of whether it is the Primary VLAN.
Candidates for Primary VLAN include any static, port-based VLAN currently
configured on the switch. (Protocol-Based VLANs and dynamic—GVRP-
learned—VLANs that have not been converted to a static VLAN cannot be the
Primary VLAN.) To display the current Primary VLAN, use the CLI
show vlan
command.
Note
If you configure a non-default VLAN as the Primary VLAN, you cannot delete
that VLAN unless you first select a different VLAN to serve as primary.
If you manually configure a gateway on the switch, it ignores any gateway
address received via DHCP or Bootp.
To change the Primary VLAN configuration, refer to “Changing the Primary
VLAN” on page 2-34.
The Secure Management VLAN
Configuring a secure Management VLAN creates an isolated network for
managing the ProCurve switches that support this feature. If you configure a
secure Management VLAN, access to the VLAN and to the switch’s manage-
ment functions (Menu, CLI, and web browser interface) is available only
through ports configured as members.
Multiple ports on the switch can belong to the Management VLAN. This
allows connections for multiple management stations you want to have
access to the Management VLAN, while at the same time allowing Man-
agement VLAN links between switches configured for the same Manage-
ment VLAN.
Only traffic from the Management VLAN can manage the switch, which
means that only the workstations and PCs connected to ports belonging
to the Management VLAN can manage and reconfigure the switch.
Figure 2-29 illustrates use of the Management VLAN feature to support man-
agement access by a group of management workstations.