预览加载中,请您耐心等待几秒...
1/10
2/10
3/10
4/10
5/10
6/10
7/10
8/10
9/10
10/10

亲,该文档总共12页,到这已经超出免费预览范围,如果喜欢就直接下载吧~

如果您无法下载资料,请参考说明:

1、部分资料下载需要金币,请确保您的账户上有足够的金币

2、已购买过的文档,再次下载不重复扣费

3、资料包下载后请先用软件解压,在使用对应软件打开

Jul 14 HYPERLINK"http://blog.ine.com/2008/07/14/private-vlans-revisited/"\o"PermanentLinktoPrivateVLANsRevisited"PrivateVLANsRevisited HYPERLINK"http://blog.ine.com/2008/07/14/private-vlans-revisited/"\l"comments"\o"Add/ViewComments"62Comments PostedbyHYPERLINK"http://blog.ine.com/?author=5"\o"VisitPetrLapukhov,4xCCIE/CCDE’swebsite"PetrLapukhov,4xCCIE/CCDEinHYPERLINK"http://blog.ine.com/category/ccie-security/advanced-security/"\o"ViewallpostsinAdvancedSecurity"AdvancedSecurity,HYPERLINK"http://blog.ine.com/category/ccie-routing-switching/security/"\o"ViewallpostsinSecurity"Security,HYPERLINK"http://blog.ine.com/category/ccie-routing-switching/switching/"\o"ViewallpostsinSwitching"Switching HYPERLINK"http://twitter.com/share?url=http%3A%2F%2Fblog.ine.com%2F2008%2F07%2F14%2Fprivate-vlans-revisited%2F&via=inetraining&text=Private%20VLANs%20Revisited&related=&lang=en&count=vertical"Tweet Duetothenon-decreasinginteresttothepostaboutPrivateVLANs,Idecidedtomakeanotherone,moredetailed–includingadiagramandverificationtechniques. Introduction Tobeginwith,recallthatVLANisessentiallyabroadcastdomain.PrivateVLANs(PVANs)allowsplittingthedomainintomultipleisolatedbroadcast“subdomains”,introducingsub-VLANsinsideaVLAN.Asweknow,EthernetVLANscannotcommunicatedirectlywitheachother–theyrequireaL3devicetoforwardpacketsbetweenseparatebroadcastdomains.ThesamerestrictionappliestoPVLANS–sincethesubdomainsareisolatedatLevel2,theyneedtocommunicateusinganupperlevel(L3/packetforwarding)device–suchasrouter. Inreality,differentVLANsnormallymaptodifferentIPsubnets.WhenwesplitaVLANusingPVLANs,hostsindifferentPVLANsstillbelongtothesameIPsubnet,yetnowtheyneedtousearouter(L3device)totalktoeachother(forexample,byusingLocalProxyARP).Inturn,theroutermayeitherpermitorforbidcommunicationsbetweensub-VLANsusingaccess-lists.Commonly,theseconfigurationsarisein“shared”environments,sayISPco-location,whereit’sbeneficialtoputmultiplecustomersintothesameIPsubnet,yetprovideagoodlevelofisolationb