As I mentioned in previous article, the PVLAN trunk feature is not widely available. However they are mentioned in the SWITCH materials. Therefore, I wanted to briefly mention how these may be used. In many cases, I find a picture is worth a million words. This happens to be one of those cases. Therefore, I provided a simple diagram for reference.
The two special types of trunks shown above are discussed in this article. The one on the right is an isolated PVLAN trunk, while the one on the left is a promiscuous PVLAN trunk. By now, most PacketU readers understand that PVLANs have isolated, community and promiscuous ports. These are typically similar to access ports in regard to VLAN tagging.
In a typical PVLAN configuration, the trunks connecting two PVLAN aware switches are constructed using normal 802.1q trunks (switchport mode trunk). This is the proper configuration only when both devices that understand that VLANs are private and should be handled accordingly. However, cases may arise when trunks need to be created between devices that lack the support for PVLANs. This is where these special PVLAN trunks come into play.
The function of these special Private VLAN trunks is that of merging the primary and secondary VLANs. These special trunk types must be either promiscuous or isolated. In this sense, promiscuous trunk ports behave a lot like normal promiscuous PVLAN ports. Like a typical promiscuous port, devices connected to the promiscuous PVLAN trunk port can communicate with all devices in the PVLAN. The only real difference is that frames can be tagged. Additionally, the interface merges the primary and secondary VLANs into a common VLAN ID.
Isolated PVLAN trunks function exactly the same in regards to tagging. However, devices connected to this type of trunk port can only communicate with promiscuous PVLAN ports. This communication can be with devices connected to regular promiscuous PVLAN ports or a promiscuous PVLAN trunk port.
The following is a comprehensive list of the port types and functions found in private VLAN configurations.
PVLAN Access Ports
- Promiscuous Port — communication can be established with all other ports in the private vlan
- Community Port — communication can be established with other ports in the same community and the promiscuous ports
- Isolated Port — communication can only be established with the promiscuous ports
- Regular Trunk Port (switchport mode trunk) — communicates VLAN information between two switches using 802.1q tagging. In regards to private VLANs, used when both devices understand PVLANs
- Promiscuous PVLAN Trunk — Functions like a promiscuous port but uses tagging and merges applicable VLANs into a common VLAN ID
- Isolated PVLAN Trunk — Functions like an isolated port but uses tagging and merges applicable VLANs into a common VLAN ID