Double Private VLAN

I want to ask if my Vswitch on the VM ware has using 1st time Private VLAN and at the N5K can I use apply second time Private VLAN?
VM Servers <--- Trunk---> N5K            
First VM has primary vlan say 100
First VM secondary vlan say 101,102,103
Second VM has primary vlan say 200
Second VM secondary vlan say 201,202,203
So will N5K able to has following PVLAN config
Primary VLAN 300
Secondary VLAN say 100,200

Vlad,
From networks connected behind router1 need to reach networks connected behind router2
------[router1]--------------gig1/4[vdmz]gig2/16----------------[router2]-------
gig1/4 is community vlan 121
gig2/16 is in community vlan 119
Primary vlan is Vlan116
VDMZ is our 6503 configured with private vlans.
some more of the config is this (and I do have a 6503 with an mscf daughter card):
interface Vlan116
description vendor-dmz public/private primary vlan
ip address 10.248.15.2 255.255.255.128 secondary
ip address 211.121.108.66 255.255.255.192
ip access-group 140 in (this one has a permit any any at the end)
no ip redirects
no ip unreachables
private-vlan mapping 117-122
ip route 10.82.35.0 255.255.255.0 211.121.108.96
(where 211.121.108.96 is address of router1)
I have a bgp peering with 211.121.108.90 which is router2.
in router1 they can see the routes advertised via bgp and also in router2 they
can see the route for 10.82.35.0 that I advertise to them via bgp.
I really appreciate your help,
Alban

Similar Messages

  • Hi all, need advice on OSPF and private vlans

    Hi all.
    I have a project to complete and need some help on the possible solution I can use.
    Basically we have ospf area 0 and the users in question are in ospf area 7 and is a stub.
    I need to route the traffic from these users out through area 0 through 3 core devices, onto an external firewall interface to be placed onto the vpn that sits on it. The firewall is not included in the ospf domain.
    My thinking was that the firewall has a default route back into the ospf domain so dont need to worry about traffic coming in, however my job is to segregate these users and take them out of our core network and place them onto an external network via this vpn.
    Not sure how to achieve this apart from static routing redistributed but surely this does not seperate their traffic only points the route to ospf?!
    I was thinking I might have to use private vlans or policy routing but when I try policy routing the policy gets ignored due to normal forwarding.
    Any help and advice would be greatly appreciated.
    Cheers
    Steve

    Steve
    Thanks, that helps.
    GRE is defintely out because apart from the 6500 GRE tunneling is not supported on the Cisco switches.
    It's good that area 7 is only for these users and not mixed up with other users.
    So if i understand correcty the 4500 interface connecting to the 6500 is in area 0 and the interface connecting to the 3550 is in area.
    Or is the 3550 connected to both areas and the 4500 totally in area 0 ?
    Can you confirm the above ?
    In terms of keeping them separate there are 2 possible choices. You can either -
    1) use VRF-LIte, although i'm not sure whether the HP switch would support this. With VRF-Lite you are in effect creating virtual devices on the same physical device. This means each virtual device has it's own routing and forwarding table so it is quite secure because you would only populate the routing table with the routes needed so there would be no way for users to jump to thes rest of your networks.
    The downside is that is can become quite complex to configure. If the 4500 is only used to connect are 7 to area 0 then that would not be a problem but the connection from the 6500 to the HP could and i don't even know whether the HP supports VRF-Lite functionality let alone how to configure it on that switch.
    But it would, at least from the 4500 to 6500 to HP provide complete separation in terms of routing and forwarding. Once it got to the HP it wouldn't but that might not be an issue.
    2) Use PBR (possibly together with acls). This is easier to configure ie. you configure PBR on the 4500 and the 6500 to get the traffic to the HP switch. But you do not get the actual separation you get with VRF-Lite ie. the traffic simply overrides the existing routing tables.
    The other thing to bear in mind with PBR is that you also have to configure the return traffic as well so each device would need multiple PBR configs.
    Again i don't know whether the HP supports PBR but it may not be an issue depending on what the routing is on the HP.
    You could also use a combination of the above ie VRF-Lite between the Cisco switches and then PBR for the last hop to the HP device.
    I should say i don't have a huge amount of experience with VRF-Lite but that should not necessarily stop you using it if it is what you need. There are lots of other people on here so i'm sure there will be other people who can help if i can't.
    It still depends on how much separation is required. VRF-Lite is definitely seen as a way to separate traffic running across a shared infrastructure, PBR is not really seen in the same way.  So it may well be worth going back to find out exactly what "segregating" user traffic means.
    I don't want to confuse the issue but it's still not entirely clear what the actual requirement is.
    Jon

  • How to setup Private VLAN in Small business switch SF200-24

    Dear All,
    According release notes 1.4 , private vlan is supported. I've upgraded my SF200-24 with firmware 1.4.0.88 and boot 1.3.5.06. The system information show firmware version 1.4.0.88 and boot version 1.3.5.06 after reboot. I can't find private vlan setup command on GUI. Please help me to setup private vlan. Thanks.

    Hi,
    Unfortunately PVLAN is not supported on 200 series. However you might be able to overcome this using general port concept.
    for example:
    isolated port - general 10P (PVID), 30U, drop tagged traffic
    community - 20UP, 30U, drop tagged traffic
    promiscuous - 30UP, 10U, 20U
    Note: primary vlan 30
    does it address your requirements?
    Aleksandra

  • Private VLan in 3550

    we are going to purchase cisco 3550 switches for our DMZs setup, we would like to utilise the Private VLAN (PVLAN) features in order to protect our individual server from any attack or any compromise servers. Can any body highlight some more on this how best is this to configure pvlans in cisco 3550 switches and is there any issues with Checkpoint Firewall.
    where I will get step by step commands. I searched on cisco site but lost myself for finding the step by step documentation.
    I find one documentation which was very good but it is for cisco 6500 series switches. please see the link for that http://www.cisco.com/warp/customer/473/90.shtml
    Thanks in advance

    Here is a link that I hope helps you with your coinfiguration. See Configuring Protected Ports portion for the PVLAN feature.
    http://www.cisco.com/en/US/partner/products/hw/switches/ps637/products_configuration_guide_chapter09186a008007e838.html
    I don't know any issues with specific vendor equipment (e.g. Checkpoint FW, etc).
    Hope this helps you,
    Don

  • Nexus 1000V private-vlan issue

    Hello
    /* Style Definitions */
    table.MsoNormalTable
    {mso-style-name:Standardowy;
    mso-tstyle-rowband-size:0;
    mso-tstyle-colband-size:0;
    mso-style-noshow:yes;
    mso-style-parent:"";
    mso-padding-alt:0cm 5.4pt 0cm 5.4pt;
    mso-para-margin:0cm;
    mso-para-margin-bottom:.0001pt;
    mso-pagination:widow-orphan;
    font-size:10.0pt;
    font-family:"Times New Roman";
    mso-ansi-language:#0400;
    mso-fareast-language:#0400;
    mso-bidi-language:#0400;}
    I need to transmit both the private-vlans (as promiscous trunk) and regular vlans on the trunk port between the Nexus 1000V and the physical switch. Do you know how to properly configure the uplink port to accomplish that ?
    Thank you in advance
    Lucas

    Control vlan is a totally seperate VLAN then your System Console. The VLAN just needs to be available to the ESX host through the upstream physical switch and then make sure the VLAN is passed on the uplink port-profile that you assign the ESX host to.
    We only need an interface on the ESX host if you decide to use L3 control. In that instance you would create or use an existing VMK interface on the ESX host.

  • Heads Up: Private VLAN Sticky-ARP DHCP Issues

    Here is the scenario:
    Private VLANs are configured on a 6500 Sup720 with SVIs routing for the PVLANs.
    DHCP Snooping and IP ARP Inspection are also configured for the PVLAN subnets.
    A DHCP Server is offering 3 day leases.
    A laptop connects to the network and receives a 3-day lease. The user leaves the office and returns 4 days later. The DHCP server offers a new lease with a different IP address. Furthermore, the previous IP address leased to the laptop has been handed out in a new lease to another host. Both systems receive their DHCP lease but have no network connectivity.
    The problem occurs because, by default, PVLAN SVIs use Sticky-ARP and never age out their ARP cache. Since the laptop has a different IP address to MAC address mapping than recorded in the Sticky-ARP cache, a violation occurs and the switch prevents the new IP address from populating the ARP table on the switch.
    Sticky-ARP is a security feature that prevents one system from stealing another systems IP address.
    Log messages show the following:
    %IP-3-STCKYARPOVR: Attempt to overwrite Sticky ARP entry
    The 6500 PVLAN configuration guide Restrictions and Guidlines section suggests that Sticky-ARP is fundamental to Private-VLANs, and the only work-around for this problem is to create manual arp entries for the new IP address. This is clearly not a viable workaround for this scenario.
    http://www.cisco.com/univercd/cc/td/doc/product/lan/cat6000/122sx/swcg/pvlans.htm#wp1090979
    However, the 6500 Command Reference shows that Sticky ARP can be disabled, but makes no reference to PVLANs
    http://www.cisco.com/univercd/cc/td/doc/product/lan/cat6000/122sx/cmdref/i1.htm#wp1091738
    There appears to be two sensible solutions to this problem:
    1) Disable Stick-ARP on the 6500 for the PVLANs. Since DHCP Snooping and IP ARP Inspection are configured, sticky-arp can be disabled without relaxing network security. This is assuming the 6500 will accept the command and will not break the existing PVLAN functionality.
    2) Extend the DHCP lease longer, to 45 or 90 days perhaps. This will catch most transient activity and keep the IP address to MAC address relationships the same, wherever possible. The downside here is that DHCP address pools could collect stale entires that would take the lease time to flush, thus reducing the overall available IPs in the pool.
    Has anyone else run into this problem? If so, what was your solution? Did you attempt either option above? I am planning on using solution #1 above, but I wanted to ping the NetPro community with this as I am sure we are not the first customer to run into this. Or are we??
    Regards,
    Brad

    Excellent question.
    Sticky-ARP is NOT intended to be a pain-in-the-butt that should disabled right away, rather, it is a security mechanism that prevents a system from stealing an active IP address on the subnet and causing a lot of problems. Sticky-ARP works best on subnets that have all static IP addressing where there is no expectation that a host would frequently change its IP address.
    Yes, I would recommend keeping Sticky-ARP on subnets with all static IP addresses.
    In DHCP subnets with no static IP addressing, DHCP Snooping and IP ARP Inspection provide the same security coverage that Sticky-ARP does, they prevent a system from claiming an illegitimate IP and MAC address. Furthermore, in DHCP subnets, it is reasonable to expect that a host would change its IP address from time to time when its lease expires.
    Sticky-ARP does not provide any addtional securtity benefits when DHCP Snooping and IP ARP Inspection are active and it only causes problems when a lease expires.
    When Cisco made Stick-ARP the default behavior for Private VLANs, they certain did not have DHCP in mind.
    In Summary, it should be known as a Best Practice that when using Private VLANs on user segments with DHCP that DHCP Snooping and IP ARP Inspection should be enabled and Sticky-ARP be disabled.
    Brad

  • Private VLAN

    Hi,
    I am creating Private VLAN on my 7606 Router on SVI interface.
    7606#sh vlan private-vlan
    Primary Secondary Type              Ports
    200     201       isolated          Fa4/13
    7606#sh run int f4/13
    Building configuration...
    Current configuration : 222 bytes
    interface FastEthernet4/13
     switchport private-vlan host-association 200 201
     switchport mode private-vlan host
     no ip address
     no cdp enable
    end
    when i connect a pc with Fa4/13 it remain "FastEthernet4/13 is down, line protocol is down (notconnect)". SVI interface is also down.
    STP-7606#sh int vlan 200
    Vlan200 is down, line protocol is down
      Hardware is EtherSVI, address is 0023.0419.1f40 (bia 0023.0419.1f40)
    Any idea?

    Hello
    here is the good link to understand the PVLAN
    http://www.cisco.com/warp/public/473/90.shtml
    regards
    Dhaval Tandel

  • Private VLAN support on actual HW

                       Hi all,
    I'm currently thinking about a private Vlan based solution for a special demand.
    Now for my initial investigation i need tio have something like a Pvlan HW support matrix.
    Means I'd like to know which switches in cisco portfolio supporting PVLAN's.
    Additional I'm wondering cause most of the PVLAN documentation relative old.
    How about PVLAN support. Is Pvlan on Access switches still (and in future) featured by Cisco?
    thanks for your comments
    Dieter

    Hi Dieter,
    You could see this detail using Cisco Feature Navigator tool which is avilable on the cisco web site.
    1. Go to below site
    http://tools.cisco.com/ITDIT/CFN/jsp/index.jsp
    2. Select the Feature button and type the Feature which you would like verify. If you press continue button, you can supported code as well as platform
    If you would like to know about any specific product support detail, please inform me, i can share information whether it supports or not.
    Inform me if you need more detail.
    Regards,
    Aru

  • Multi-VRF CE with Private VLANs

    Does anyone know if you can implement a VRF instance on a private vlan? I would assume so, and will lab it out as time permits, but was curious if anyone had tried it/knows one way or the other.

    Since both the platforms support VRF lite and MPLS VPN, you can use Frame-Relay as the encapsulation for sub interfaces with local DLCI switching.
    As the VRF configuration is not media dependent.
    HTH-Cheers,
    Swaroop
    Router 1
    interface Serial0/0
    no ip address
    encapsulation frame-relay
    no keepalive
    !--- This command disables LMI processing.
    interface Serial0/0.1 point-to-point
    !--- A point-to-point subinterface has been created.
    ip address 172.16.120.105 255.255.255.0
    ip vrf forwarding xxx
    frame-relay interface-dlci 101
    !--- DLCI 101 has been assigned to this interface
    Router 2
    interface Serial0/0
    no ip address
    encapsulation frame-relay
    no keepalive
    !--- This command disables LMI processing.
    interface Serial0/0.1 point-to-point
    !--- A point-to-point subinterface has been created.
    ip vrf forwarding xxx
    ip address 172.16.120.120 255.255.255.0
    frame-relay interface-dlci 101
    !--- DLCI 101 has been assigned to this interface

  • Private Vlan and Switchport Protected

    Dear All,
    My core switch is 4500 which support Private Vlan. However, I have several closet switch (2950) which only support Switchport Protected. 4500 and each 2950 are connected with trunk using fiber.
    How can I config PC at 2950_Switch1 cannot communicate to PC at 2950_Switch2 (all fastethernet port on both 2950 are at the same vlan and same subnet)?
    Thanks.
    C.K.

    Hi C.k.,
    I believe you can use switchport protected feature along with port blocking feature to accomplish this. First have your switch ports configured as protected ports on which you dont want the traffic to flow and then configure those ports to deny unknown unicast and multicast using the " port-blocking feature ".
    Try that and let us know.
    http://www.cisco.com/univercd/cc/td/doc/product/lan/cat2950/12120ea2/2950scg/swtrafc.htm#wp1174968
    HTH,
    -amit singh

  • Switches 2950 with private-vlan

    Hi experts!
    Do you know if switches 2950 suport private-vlan? I upgrade IOS and try to configure PVLAN, but this switch model dont have the interface mode command "switchport private-vlan".
    best regards,
    Rodrigo A.

    See the below matix:-
    http://www.cisco.com/en/US/products/hw/switches/ps708/products_tech_note09186a0080094830.shtml
    HTH>

  • Private VLAN support on Cisco SF220

    Hi!
    is there a plan to add support of Private VLANs on SF220?

    Hi,
    We currently do not have plans to support Private VLANs.

  • Private VLANs - is this configuration right?

    Hi
    I have a 4500 that has a vlan (10) on it that none of the clients should talk to each other. I am going to configure this as a isolated vlan. This VLAN is propagated to a 6500 that has the IP address of this VLAN, from what I have read I need to create a primary vlan (99) and then create the client vlan (10) as a isolated vlan within this (99).
    Is this correct?
    If anyone has a good doc on PVLANs please let me know! The docs on Cisco seem to be lacking.
    Cheers

    Here is an example.. Vlan 83 is the promiscuous VLAN, I left in a port on vlan 230 that has a host on it.
    no file verify auto
    spanning-tree mode pvst
    spanning-tree extend system-id
    spanning-tree vlan 83,100-101,210,230,248-250 priority 24576
    vlan internal allocation policy ascending
    vlan 83
    name DMZ_VLAN
    private-vlan primary
    private-vlan association 100-101,210,230,248
    vlan 100
    name hinfwe-vlan
    private-vlan community
    vlan 101
    name hinneo-vlan
    private-vlan community
    vlan 210
    name IPASS
    private-vlan community
    vlan 230
    name DNS-GSS
    private-vlan community
    vlan 248
    name ADP-Internal
    private-vlan community
    interface GigabitEthernet1/0/1
    description GSS-01 83.200
    switchport private-vlan host-association 83 230
    switchport mode private-vlan host
    no logging event link-status
    speed 100
    duplex full
    no snmp trap link-status
    spanning-tree portfast
    spanning-tree guard root
    interface GigabitEthernet1/0/24
    description Firewall_Uplink
    switchport access vlan 83
    switchport private-vlan mapping 83 100-101,210,230,248-250
    switchport mode private-vlan promiscuous
    speed 1000
    duplex full
    spanning-tree portfast
    spanning-tree guard root
    HTH
    CHris

  • Private vlan question

    I am replacing a standard set of switches out with ones that can support PVLAN's. All our switches currently have their ip address on vlan 1 and that is the subnet which the default gateway resides. The second switch acts as a redundant switch and will need the same vlans as the primary. Currently they are etherchanneled together. I want to setup a single private vlan with one isolated vlan and several community vlans. My question is where do I put the IP address? Do I still setup a vlan 1 interface as I have done all along? Or do I put the addrss on the primary private vlan? And I assume I will need to setup a trunk between the two switches, vs. etherchannel?

    Private VLANs provide Layer 2 isolation between ports within the same private VLAN. There are three types of private VLAN ports:
    •Promiscuous—A promiscuous port can communicate with all interfaces, including the community and isolated ports within a private VLAN.
    •Isolated—An isolated port has complete Layer 2 separation from other ports within the same private VLAN except for the promiscuous port. Private VLANs block all traffic to isolated ports except traffic from promiscuous ports. Traffic received from an isolated port is forwarded only to promiscuous ports.
    •Community—Community ports communicate among themselves and with their promiscuous ports. These interfaces are isolated at Layer 2 from all other interfaces in other communities or isolated ports within their private VLAN.
    PVLANS are also knows as secondary vlans, they are always associated to primary vlans so they can communicate to other devices outside their subnet through the default gateway. The management ip address or sc0 if it's CAtOS will always be in primary vlan or if native IOS and it's interface vlan it will always be the primary vlan. so, to answer your question, the management ip address will be in primary vlan.
    –You cannot use the inband port, sc0, in a private VLAN.
    Note: With software release 6.3(1) and later releases, you can configure the sc0 port as a private VLAN port; however, you cannot configure the sc0 port as a promiscuous port.

  • Private Vlan config

    I have a question regarding private Vlan config. I have a DMZ switch where I need to be able for a particuilar server to communicate to the reset of the servers on port 8686 and deny the rest of the communications between them. I have this server on a poremiscuios mode and the other servers on isolated ports.For security reason how can apply this access list? on which vlan? I am running IOS on the switch connecting these servers. Thanks for your help

    the port is that the server(10.3.1.50. 255.255.0.0) that need to talk to all server is attached to:
    interface GigabitEthernet1/0/18
    description DZ1WEBSD001
    switchport private-vlan host-association 50 51
    switchport mode private-vlan promiscuous
    speed 100
    duplex full
    no mdix auto
    The subnet is 10.3.1.0 255.255.0.0
    Basically the 10.3.1.50 need to talk to all servers on this subnet on port 8686 and deny evrything else
    Thanks

Maybe you are looking for

  • Wrong images appearing in project window / timeline

    I'm doing a SIMPLE slideshow project for a frient. I've got a file folder of images that I imported into CS5. In the timeline the correct images are not appearing when placed from the timeline. Even in the Project folder most of the images are not wh

  • I ordered a case for my iPad mini retina display and I doesn't fit

    I ordered a case I really liked and it doesn't fit? Why is that and where app an I get a new one?

  • Workflow Notification Issue r12

    Hi I have two issues with Workflow notification in r12. 1. Users get notification with a file attached called notification.html. This is not required. How can I stop workflow attaching this file when sending emails. 2. How can I unanimously change no

  • Oracle NoSQL YCSB - continuously increasing execution time

    Greetings, currently I am testing several nosql databases using YCSB. I am new to that type of databases, but I have already tested few of them. I am using VM with 2GB RAM and hosted on Win 7. Even though it is not recommended, since I am working in

  • Change Process Order BAPI FM?

    Hi friends, can you help me with this issue? I'm trying to change a process order (tx: cor2) but the bapi BAPI_PROCORD_CHANGE only allow me to change header data, i need to change components data (add, change, delete a material).  Any suggestions?...