Routelearn.net
Course menu

Course 4: VLANs and TrunksLesson 1.2 (2 of 7 in this course)10 of 91 in the CCNA series

Private VLANs

Share one subnet and gateway, while controlling which servers can talk to each other directly.

Advanced · 12 min read · Before this: VLAN

Private VLANs (PVLANs) are a way of dividing one VLAN, the primary VLAN, into secondary VLANs that restrict which ports can communicate at Layer 2 while all of them keep the same IP subnet. Isolated ports can reach only promiscuous ports, community ports can reach their own community and promiscuous ports, and promiscuous ports (usually the gateway) can reach every port.

In simple terms: Private VLANs let servers share one subnet and one gateway while stopping them from talking to each other directly, unless you allow it.

The situation

RouteLearn Hosting has several customer servers on one switch. Two customers each have a pair of servers that must talk to each other. Two independent customers each have one server that must not talk directly to its neighbours. Every server needs the gateway.

An ordinary VLAN would let all of these hosts reach each other at Layer 2. A Private VLAN (PVLAN) restricts that communication while they keep sharing one IP subnet.

How a PVLAN is organised

A PVLAN is a primary VLAN associated with secondary VLANs:

VLANTypeRole in the example
100PrimaryTies the customer groups to the shared gateway path
101CommunityCustomer Alpha's two servers
102CommunityCustomer Beta's two servers
103IsolatedIndependent customers' servers

These are associations, not nested VLAN tags. A primary VLAN can have one isolated secondary and any number of community secondaries.

Port roleDirect Layer 2 communication allowed with
PromiscuousAll associated community and isolated hosts
CommunityHosts in the same community, and associated promiscuous ports
IsolatedAssociated promiscuous ports only

"Promiscuous" here is a PVLAN port role, not packet-capture mode.

The hosting network

All addresses use mask 255.255.255.0, and every server's gateway is 192.168.10.1.

DeviceSwitch portIP addressRole
Gateway R1Gi1/0/1192.168.10.1Promiscuous
Alpha A1Gi1/0/2192.168.10.11Community 101
Alpha A2Gi1/0/3192.168.10.12Community 101
Beta B1Gi1/0/4192.168.10.21Community 102
Beta B2Gi1/0/5192.168.10.22Community 102
Independent C1Gi1/0/6192.168.10.31Isolated 103
Independent C2Gi1/0/7192.168.10.32Isolated 103

R1 connects with an ordinary untagged Ethernet link to the switch's promiscuous port. It doesn't need to understand the secondary VLAN structure at all.

Follow three conversations

R1 gatewayGi1/0/1 · promiscuousSW1comm 101A1.11comm 101A2.12comm 102B1.21comm 102B2.22isolated 103C1.31isolated 103C2.32
  1. 1. A1 → A2: works. A1 sees A2 as local and ARPs for its MAC. Both are in community 101, so the switch forwards it.
  2. 2. A1 → B1: blocked. Same /24, but different communities. The switch won't forward the ARP or the traffic to B1.
  3. 3. C1 → C2: blocked. Both are in isolated VLAN 103, yet isolated ports can't reach each other, for broadcasts like ARP or for unicast.
  4. 4. C1 → R1: works. Every host can reach its associated promiscuous port, so C1 and C2 both reach the gateway.

Why: IP addressing says the destination is local, but the switch only forwards between port roles that the table above allows. Without that Layer 2 path, even ARP can't complete.

What PVLANs do, and what still needs policy

PVLANs restrict local Layer 2 forwarding. They don't encrypt traffic or inspect applications. If the gateway offers a routed path between hosts, its own policy (ACLs, firewall rules) must enforce the restrictions you need. Internet access needs suitable routing, and where applicable firewall rules and NAT; this lab tests local forwarding only.

Configuration lab

Objective: allow communication within each community and toward the gateway; block direct communication between communities and between isolated hosts.

⚠️ These configurations are based on Cisco documentation and haven't been run in a lab here. Use a Catalyst switch and software image that supports PVLANs, start from a fresh lab configuration, and adjust interface names to your equipment.

Step 1: create the VLAN relationships

configure terminal vtp mode transparent vlan 101 name ALPHA private-vlan community exit vlan 102 name BETA private-vlan community exit vlan 103 name INDEPENDENT private-vlan isolated exit vlan 100 name HOSTING_PRIMARY private-vlan primary private-vlan association 101-103 exit

VTP transparent mode keeps the VLAN configuration local (VTP versions 1 and 2 can't carry PVLANs).

Step 2: the gateway connection

interface GigabitEthernet1/0/1 switchport switchport mode private-vlan promiscuous switchport private-vlan mapping 100 101-103 no shutdown exit

The promiscuous port is mapped to all three secondary VLANs.

Step 3: every host connection

interface range GigabitEthernet1/0/2 - 3 switchport switchport mode private-vlan host switchport private-vlan host-association 100 101 no shutdown exit interface range GigabitEthernet1/0/4 - 5 switchport switchport mode private-vlan host switchport private-vlan host-association 100 102 no shutdown exit interface range GigabitEthernet1/0/6 - 7 switchport switchport mode private-vlan host switchport private-vlan host-association 100 103 no shutdown exit end copy running-config startup-config

Step 4: R1

configure terminal interface GigabitEthernet0/0 ip address 192.168.10.1 255.255.255.0 no shutdown exit end copy running-config startup-config

R1 Gi0/0 connects to SW1 Gi1/0/1. Configure the servers by hand from the addressing table, and allow ICMP on them for the ping tests.

Step 5: verify the configuration

show vlan private-vlan show interfaces GigabitEthernet1/0/1 switchport show interfaces GigabitEthernet1/0/2 switchport show interfaces GigabitEthernet1/0/6 switchport show interfaces status

The output should confirm these expected values (not captured output from a lab):

ItemExpected
VLAN 100Primary
VLAN 101, 102Community, associated with 100
VLAN 103Isolated, associated with 100
Gi1/0/1Promiscuous; maps 100 to 101–103
Gi1/0/2–3Host association 100/101
Gi1/0/4–5Host association 100/102
Gi1/0/6–7Host association 100/103

Step 6: prove the forwarding behaviour

Test (both directions where it applies)Expected
Every server → 192.168.10.1Works
A1 ↔ A2Works
B1 ↔ B2Works
A1 ↔ B1Blocked
C1 ↔ C2Blocked
C1 ↔ A1Blocked

A failed ping on its own doesn't prove isolation. First confirm the same endpoint can reach the gateway and that its firewall allows the test. The lab succeeds when the permitted paths work and the restricted paths stay blocked.

Troubleshooting

SymptomInvestigate first
No host can reach the gatewayGateway link, its IP settings, the promiscuous role and its mappings
One community can't reach the gatewayThat VLAN's association, the host assignment, and whether the promiscuous port maps it
Same-community hosts can't talkEndpoint settings, local firewalls and host associations
Different communities talk directlyWrong port roles, ordinary access ports, or another forwarding path
Works on one switch, fails across twoPVLAN support, consistent associations on both switches, trunk configuration

If a secondary VLAN is left out of the promiscuous port's mapping, that group can't reach the gateway in either direction; add it with switchport private-vlan mapping add. Across switches, a standard trunk must carry the primary and the secondary VLANs, with the same associations configured on each switch. Specialised PVLAN trunk modes need their own platform-specific design.

Practice with explained answers

Predict · scenario 1

Why can two isolated hosts share a subnet but fail to communicate directly?

Predict · scenario 2

Does putting a server in a community VLAN isolate it from every other server?

Predict · scenario 3

The first ping between two permitted hosts fails, then the next ones work. Is the configuration wrong?

✅ Cheat sheet
  • Promiscuous reaches every associated host.
  • Community reaches its own community and promiscuous ports.
  • Isolated reaches promiscuous ports only, even within the same isolated VLAN.
  • One primary, at most one isolated, any number of communities, one shared subnet.
  • PVLANs control local forwarding; routing policy still controls what the gateway allows.