Private VLAN (PVLAN) on Cisco Catalyst Switch

Hello Azm

Yes, it is possible to configure multiple trunk ports as promiscuous ports for a single primary VLAN. You would configure this if you want to span a primary VLAN over three switches for example.

Secondly, it is possible as well to configure a single trunk port as a promiscuous port for multiple primary VLANs. This again, would be the case if you have multiple primary VLANs that you want to span over more than one switch. Specifically, Cisco states:

Multiple private VLAN pairs can be specified using the switchport private-vlan mapping trunk command so that a promiscuous trunk port can carry multiple primary VLANs.

Also, Cisco states:

The maximum number of unique private VLAN pairs supported by the switchport private-vlan mapping trunk command is 500. For example, one thousand secondary VLANs could map to one primary VLAN, or one thousand secondary VLANs could map one to one to one thousand primary VLANs.

However, keep the following guidelines in mind:

  1. According to Cisco, if you are using private VLANs and you want to span them over several switches, “You should use standard trunk ports if both switches undergoing trunking support PVLANs.”
  2. You would use promiscuous trunk ports only in the case where you are connecting to a switch that does not have PVLAN capability. You can find more on this in Cisco’s official documentation.

I hope this has been helpful!

Laz

1 Like