Vlan Untagged / PVID
Hello All,
Everytime I need to configure a port for an equipment (like a PC) in a vlan I set the port "untagged" Vlan3 and also set the PVID to 3.
I'am wondering which case needs to get a PVID different from the Untagged Vlan.
Just curious.
If someone has an example...
0
Comments
-
Hi @Alex,
We usually set ports connected with end-devices (For example, your PC) Untagged because end-devices usually cannot recognized tagged packets.
Tagged out setting is usually used when ports connected with another switches and you want packets to be sent to certain VLAN so that you need tagged out.
Ryan
0 -
Hi Ryan,
Ok but in which case you set PVID different from the untagged ?
0 -
Hi @Alexif you create a VLAN, for example VLAN50 (192.168.50.xxx) and you want certain switch ports to assign the 192.168.50.xxx addresses then you connect the devices in the ports with the PVID. Example from port 10 to port 15 of the switch you set the PVID to 50 and the 5 ports with this configuration will assign the IP 192.168.50.xxx.
All other ports will not assign ip 192.168.50.xxx but 192.168.2.xxx.Bye
0 -
Hi guys,
Thanks for your discussion.
About @Alex's question, we usually set a port PVID with untagged out.
If we set a port as tagged out, the PVID is usually useless under this setting.
Ryan
0 -
Alex said:I'am wondering which case needs to get a PVID different from the Untagged Vlan.
...If someone has an example...
please note that you can set more than one VLAN to untagged in outgoing direction. In the incoming direction, on the other hand, it is a 1 to 1 relationship (determined by the PVID).
When do you need this?
In 99.99 percent of cases, you do not need this. But in some rare cases you can use this.
The most important use cases are so-called "asymmetric VLANs".
Please read the following:
https://www.manualslib.com/manual/225989/D-Link-Web-Smart-Des-1210-28p.html?page=43
ftp://ftp.d-link.co.za/DFL/dfl860/SetupGuides/Asymmetric VLAN with DAP(0716182927).pptx
Ultimately, this is the underlying technology behind so-called "private VLANs". Cisco calls this "community private VLAN" in contrast to "private vlan edge", which is referred to as "protected port" in other manufacturers.
https://www.cisco.com/c/en/us/td/docs/switches/datacenter/nexus5000/sw/configuration/guide/cli/CLIConfigurationGuide/PrivateVLANs.html#pgfId-1182268
regards,
Steffen
0
Categories
- All Categories
- 415 Beta Program
- 2.4K Nebula
- 144 Nebula Ideas
- 94 Nebula Status and Incidents
- 5.6K Security
- 237 USG FLEX H Series
- 267 Security Ideas
- 1.4K Switch
- 71 Switch Ideas
- 1.1K Wireless
- 40 Wireless Ideas
- 6.3K Consumer Product
- 247 Service & License
- 384 News and Release
- 83 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.2K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 83 About Community
- 71 Security Highlight