- Community Home
- >
- Networking
- >
- Switching and Routing
- >
- Comware Based
- >
- How to use PRIVATE VLAN across switches
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-17-2020 02:36 AM
07-17-2020 02:36 AM
How to use PRIVATE VLAN across switches
Hi,
I have to use private vlan to isolate client but my configuration doesn't seem to work..
My topology is :
2 computeur ( PC1 : 10.10.10.1/24 and PC2 10.10.10.2/24)
1 ACCESS Switch where the computer are plugged.
1 DISTRIBUTION Switch
1 Router ( Gateway 10.10.10.254/24)
I'm working with HP 5130 using Comware 7.
I tried this configuration
ACCESS
vlan 10
private-vlan primary
private-vlan secondary 100
#
vlan 100
private-vlan isolated
#
int gi 1/0/1
description UPLINK
port link-type trunk
undo port trunk permit vlan 1
port trunk permit vlan 10 100
port trunk pvid vlan 123
#
int gi 1/0/2
description PC1
port access vlan 100
port private-vlan host
#
int gi 1/0/3
description PC2
port access vlan 100
port private-vlan host
DISTRIBUTION
vlan 10
private-vlan primary
private-vlan secondary 100
#
vlan 100
private-vlan isolated
#
int gi 1/0/1
description UPLINK
port link-type trunk
undo port trunk permit vlan 1
port trunk permit vlan 10 100
port trunk pvid vlan 123
port private-vlan 10 promiscous
#
int gi 1/0/2
description DOWNLINK
port link-type trunk
undo port trunk permit vlan 1
port trunk permit vlan 10 100
port trunk pvid vlan 123
port private-vlan 100 trunk secondary
PC can't ping each one but they can't ping gateway too.
If I don't put the private-vlan host option on the Client interfaces, I can ping the gateway.
thanks in advance for help
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-17-2020 03:02 AM
07-17-2020 03:02 AM
Re: How to use PRIVATE VLAN across switches
Hello Julien_dpr,
Please configure acording to to the following configuration guide p.163 onwards:
https://support.hpe.com/hpesc/public/docDisplay?docId=a00017775en_us&docLocale=en_US
Also please note the following requirements are met:
Make sure the following requirements are met:
For a promiscuous port:
− The primary VLAN is the PVID of the port.
− The port is an untagged member of the primary VLAN and secondary VLANs.
For a host port:
− The PVID of the port is a secondary VLAN.
− The port is an untagged member of the primary VLAN and the secondary VLAN.
A trunk promiscuous or trunk secondary port must be a tagged member of the primary
VLANs and the secondary VLANs.
• VLAN 1 (system default VLAN) does not support the private VLAN configuration
Hope this helps!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-27-2020 12:16 PM
07-27-2020 12:16 PM
Re: How to use PRIVATE VLAN across switches
Hello,
I followed the guide to try a configuration but the private vlan is not working across switches as you can see in this example :
https://ibb.co/1fyQ6Qn
My goal here is to have laptops connected to my access's switches and they must be able to ping our gateway on the router ( 10.10.10.254 ) but they can't ping with each other. I'm using private vlan and not port-isolated because i will have multiple acces's switches connected to my distribution's switch.
So, to reach my goal i tried the following configuration (only showing vlan configuration on interfaces) :
--------------- DISTRIBUTION ---------------
vlan 10
private-vlan primary
private-vlan secondary 100
vlan 100
private-vlan isolated
int gi 1/0/1
port access vlan 10
port private-vlan 10 promiscuous
int gi 1/0/2
port link-type hybrid
port hybrid vlan 10 100 tagged
port privat-vlan 100 trunk secondary------------- ACCES ---------------------
vlan 10
private-vlan primary
private-vlan secondary 100
vlan 100
private-vlan isolated
int gi 1/0/1
port access vlan 100
port private-vlan host
int gi 1/0/2
port access vlan 100
port private-vlan host
int gi 1/0/3
port link-type hybrid
port hybrid vlan 10 100 tagged
And with this configuration my laptops can't communicate with each other but they can't ping the gateway neither, and i don't understand why.
Also, when i'm configuring the hosts on the distribution, they can communicate with the router but they can't with each other. So the problem seems to be during the tagged communication across switches to reach the gateway.
I tried antoher configuration on the acces's switch as well :
------- ACCESS ------
vlan 100
name secondary vlan
int gi 1/0/1
port access vlan 100
int gi 1/0/2
port access vlan 100
int gi 1/0/3
port link-type hybrid
port hybrid vlan 10 tagged
If you could help me, it would be much appreciate
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-29-2020 02:49 AM
07-29-2020 02:49 AM
Re: How to use PRIVATE VLAN across switches
Hello Julien_dpr,
Please try under port int gi 1/0/3 on access switch to add:
port private-vlan 100 trunk secondary
Hope this helps
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-30-2020 12:56 AM
07-30-2020 12:56 AM
Re: How to use PRIVATE VLAN across switches
I tried to add trunk secondary on the uplink's interface of the acces's switch but it's changing nothing.
I still can't ping the gateway of my LAN.
Best Regards,
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-30-2020 03:21 PM
07-30-2020 03:21 PM
Re: How to use PRIVATE VLAN across switches
Hello Julien_dpr,
As it is possible that the order of operations could be different and you make a lot of changes and tests that some additional commands are added under the port configuration.
Please delete the port configuration for the ports connecting the two switches and use the following port configuration for both ports for testing - on access 1/0/3 on distri 1/0/2, depending on your configuration :
-------------------------------------
port link-type trunk
port trunk permit vlan all
-------------------------------------
or
------------------------------------
port link-type hybrid
undo port hybrid vlan 1
port hybrid vlan 10 100 untagged
port hybrid pvid vlan 10
-------------------------------------
Please check the configuration of the port that there is no other configuration left as when you add private vlan command it is adding additional settings to the port.
Hoper this helps!