Cisco IOS Private VLANs: Isolated, Community, Promiscuous - 夜莺博客

Cisco IOS Private VLANs: Isolated, Community, Promiscuous

A private VLAN enforces Layer 2 isolation inside a single IP subnet. Hosts share the gateway and the subnet mask, but cannot talk to each other directly - which is exactly what hosting providers, hotels, university labs and multi-tenant DMZs need without burning an IP subnet per tenant. This is the configuration model and the traps that make PVLANs look broken.

The Three Port Roles

Port Can talk to Typical use
Promiscuous Everyone in the PVLAN domain Router, firewall, load balancer, shared service
Isolated (host) Promiscuous only - not even other isolated ports Untrusted tenants, guest jacks, customer servers
Community (host) Same community + promiscuous A tier or customer with multiple boxes

Two structural facts: one primary VLAN per PVLAN domain, at most one isolated secondary VLAN, and as many community secondary VLANs as you need. Both isolated and community host ports use the same port mode (private-vlan host) - the VLAN type decides behaviour, not the port command.

Step 1 - Create the VLANs

vlan 100
 name PVLAN_PRIMARY
 private-vlan primary
 private-vlan association 101,102
!
vlan 101
 name PVLAN_ISOLATED
 private-vlan isolated
!
vlan 102
 name PVLAN_COMMUNITY_A
 private-vlan community

A VLAN cannot become a PVLAN while access ports are assigned to it, and VLANs 1 and 1002-1005 are excluded. Note that the association is configured on the primary VLAN, and it must list every secondary.

Step 2 - Promiscuous Port (Gateway Facing)

interface TenGigabitEthernet1/1/5
 description Uplink-to-Gateway-PROMISCUOUS
 switchport
 switchport mode private-vlan promiscuous
 switchport private-vlan mapping 100 101,102

The mapping tells the promiscuous port which secondaries it serves. Omitting a secondary here produces the classic partial failure: hosts in that secondary can still reach each other (intra-secondary traffic stays inside the switch) but cannot reach the gateway at all.

Step 3 - Host Ports

interface range GigabitEthernet1/0/1 - 2
 description Isolated-Hosts
 switchport mode private-vlan host
 switchport private-vlan host-association 100 101
 spanning-tree portfast

interface GigabitEthernet1/0/5
 description Community-A-Host
 switchport mode private-vlan host
 switchport private-vlan host-association 100 102
 spanning-tree portfast

Step 4 - Layer 3: SVI for the Primary VLAN Only

interface Vlan100
 description PVLAN-Gateway
 ip address 10.20.0.1 255.255.255.0
 private-vlan mapping 101,102
 no shutdown

Secondary VLANs never get an active SVI. If you configure one, it stays down - and if you forget the SVI private-vlan mapping, hosts will not reach their default gateway even though the promiscuous port is perfect. This is the single most common PVLAN ticket.

Verification

show vlan private-vlan
show interfaces TenGigabitEthernet1/1/5 switchport
show interfaces GigabitEthernet1/0/1 switchport | include private-vlan
show mac address-table vlan 101
show ip interface brief

Expect to see the isolated host MACs twice if you look at the MAC table - once blocked in the secondary VLAN context, once in the primary - which is normal and not a loop.

The Security Gap Everyone Misses

PVLAN isolation is Layer 2 only. If the gateway routes the packet, it can land back in the same primary VLAN and be delivered to another isolated host - so two tenants can reach each other through the router. Close that with a private VLAN ACL or an ACL on the SVI: permit the subnet to everything except its own subnet, then deny intra-subnet traffic that would arrive via routing. Without it, PVLAN is isolation against broadcast domains, not against a determined tenant.

Cross-Switch Deployments

Trunks need to carry the primary and secondary VLANs, and the PVLAN policy follows the tags. Most production deployments stay single-switch or within a stack/M-LAG pair for exactly this reason; when stretching further, verify with show vlan private-vlan on both ends before declaring success. Related reading: the Arista EOS PVLAN equivalent if your fabric is not all-Cisco, and DHCP option 82 for identifying tenants on a shared access layer.

原文链接:https://www.cisco.com/c/en/us/support/docs/lan-switching/private-vlans-pvlans-promiscuous-isolated-community/40781-194.html