Используя PVLANS в сочетании со стандартными VLAN

Необходимо смочь отослать запросы ARP наверняка. То, что можно сделать, является ARP весь дюйм/с в сети один за другим, и посмотрите, кто отвечает.

0
задан 20 October 2012 в 02:08
1 ответ

The way that PVLAN operates is that traffic transmitted into an isolated port is actually mapped into another VLAN (the aux VLAN). The promiscuous port, in turn, transmits frames from both the primary and aux VLAN's to its connected host. Frames received on the promiscuous port go into the primary VLAN.

What this means is that the promiscuous port and the normal ports can communicate normally, the normal ports can send traffic -to- the isolated ports but will receive no traffic back and traffic sent from the isolated ports will only be seen at the promiscuous port. The normal ports will continue to operate as expected.

So - if you're OK with the normal ports being able to send traffic to the isolated ports (but not vice-versa) then the rest of the setup should work.

The use of community ports (instead of normal/non-PVLAN ports) would insure that traffic sent from said ports would never be seen on the isolated ports while still allowing full communication otherwise. This would generally be the way to go if you want the isolated hosts truly isolated.

1
ответ дан 4 December 2019 в 21:37

Теги

Похожие вопросы