TP-Link T2600G-52TS TL-SG3452 T2600G-52TS V1 User Guide - Page 102

The Elements of a Private VLAN, Promiscuous port, Host port, Primary VLAN, Secondary VLAN, Features

Page 102 highlights

devices need to identify Primary VLANs but not Secondary VLANs. Therefore, they can save VLAN resources without considering the VLAN configuration in the lower layer. Meanwhile, the service provider can assign each user an individual Secondary VLAN, so that users are separated at the Layer 2 level. Private VLAN technology is mainly used in campus or enterprise networks to achieve user Layer-2-separation and to save VLAN resources of uplink devices.  The Elements of a Private VLAN Promiscuous port: A promiscuous port connects to and communicates with the uplink device. The PVID of the promiscuous port is the same with the Primary VLAN ID. One promiscuous port can only join to one Primary VLAN. Host port: A host port connects to and communicates with terminal device. The PVID of the host port is the same as the Secondary VLAN ID. One host port can only belong to one Private VLAN. Primary VLAN: A Private VLAN has one Primary VLAN and one Secondary VLAN. Primary VLAN is the user VLAN uplink device can identify but it is not the actual VLAN the end user is in. Every port in a private VLAN is a member of the primary VLAN. The primary VLAN carries unidirectional traffic downstream from the promiscuous ports to the host ports and to other promiscuous ports. Secondary VLAN: .Secondary VLAN is the actual VLAN the end user is in. Secondary VLANs are associated with a primary VLAN, and are used to carry traffic from hosts to uplink devices. There are two types of secondary VLANS:  Isolated VLAN-The VLAN that an isolated port is associated with is called isolated VLAN. Each isolated VLAN must bind to a primary VLAN.  Community VLAN-The VLAN that a community port is associated with is called community VLAN. Each community VLAN must bind to a primary VLAN.  Features of Private VLAN 1. A Private VLAN contains one Primary VLAN and one Secondary VLAN. 2. A VLAN cannot be set as the Primary VLAN and Secondary VLAN simultaneously. 3. A Secondary VLAN can only join one private VLAN. 4. A Primary VLAN can be associated with multi-Secondary VLANs to create multi-Private VLANs.  Private VLAN Implementation To hide Secondary VLANs from uplink devices and save VLAN resources, Private VLAN containing one Primary VLAN and one Secondary VLAN requires the following characteristics:  Packets from different Secondary VLANs can be forwarded to the uplink device via promiscuous port and carry no corresponding Secondary VLAN information.  Packets from Primary VLANs can be sent to end users via host port and carry no Primary VLAN information. 92

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278

92
devices need to identify Primary VLANs but not Secondary VLANs. Therefore, they can save
VLAN resources without considering the VLAN configuration in the lower layer. Meanwhile, the
service provider can assign each user an individual Secondary VLAN, so that users are separated
at the Layer 2 level.
Private VLAN technology is mainly used in campus or enterprise networks to achieve user
Layer-2-separation and to save VLAN resources of uplink devices.
The Elements of a Private VLAN
Promiscuous port:
A promiscuous port connects to and communicates with the uplink device.
The PVID of the promiscuous port is the same with the Primary VLAN ID. One promiscuous port
can only join to one Primary VLAN.
Host port:
A host port connects to and communicates with terminal device. The PVID of the host
port is the same as the Secondary VLAN ID. One host port can only belong to one Private VLAN.
Primary VLAN:
A Private VLAN has one Primary VLAN and one Secondary VLAN. Primary VLAN
is the user VLAN uplink device can identify but it is not the actual VLAN the end user is in. Every
port in a private VLAN is a member of the primary VLAN. The primary VLAN carries unidirectional
traffic downstream from the promiscuous ports to the host ports and to other promiscuous ports.
Secondary VLAN:
.Secondary VLAN is the actual VLAN the end user is in. Secondary VLANs are
associated with a primary VLAN, and are used to carry traffic from hosts to uplink devices. There
are two types of secondary VLANS:
Isolated VLAN
The VLAN that an isolated port is associated with is called isolated VLAN.
Each isolated VLAN must bind to a primary VLAN.
Community VLAN
The VLAN that a community port is associated with is called community
VLAN. Each community VLAN must bind to a primary VLAN.
Features of Private VLAN
1.
A Private VLAN contains one Primary VLAN and one Secondary VLAN.
2.
A VLAN cannot be set as the Primary VLAN and Secondary VLAN simultaneously.
3.
A Secondary VLAN can only join one private VLAN.
4.
A Primary VLAN can be associated with multi-Secondary VLANs to create multi-Private
VLANs.
Private VLAN Implementation
To hide Secondary VLANs from uplink devices and save VLAN resources, Private VLAN
containing one Primary VLAN and one Secondary VLAN requires the following characteristics:
Packets from different Secondary VLANs can be forwarded to the uplink device via
promiscuous port and carry no corresponding Secondary VLAN information.
Packets from Primary VLANs can be sent to end users via host port and carry no Primary
VLAN information.