Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

private vlan trouble?

I have the following private vlan configuration:

What do I have to do in order for the networks sitting behind router1 and router2

to talk to each other.

I have verified that both routers have the correct routes on their routing table

vlan 116

name primary

private-vlan primary

private-vlan association 117-122

vlan 119

name torouter2

private-vlan community

vlan 121

name torouter1

private-vlan community

interface GigabitEthernet2/16

description Connection to router2


switchport private-vlan host-association 116 119

switchport mode private-vlan host

no ip address

speed 100

duplex full

spanning-tree portfast

interface GigabitEthernet1/4

description Connection to router1


switchport private-vlan host-association 116 121

switchport mode private-vlan host

no ip address

speed nonegotiate

spanning-tree portfast

thank you very much,



Re: private vlan trouble?

Hello Alban,

Where's your promiscous port?

Switch# configure terminal

Switch(config)# interface Gig X/X

Switch(config-if)# switchport mode private-vlan promiscuous

Switch(config-if)# switchport private-vlan mapping 116 add 119 121

Switch(config-if)# end

let us know,


New Member

Re: private vlan trouble?


thank you.

I do not have a promiscuos port configured.

If I configure one what do I connect to it?



Re: private vlan trouble?

I think you should read the following document for a better clarification on the subject:

this is for 3560, but you'll find it on other IOS versions and platforms.

the promiscous port will be the port that is allowed to communicate with all other interfaces, so usually is the port connected to a router.

I'm not what is your requirements on this scenario.

Please give us more details, we could find a better configuration for you.


New Member

Re: private vlan trouble?


From networks connected behind router1 need to reach networks connected behind router2


gig1/4 is community vlan 121

gig2/16 is in community vlan 119

Primary vlan is Vlan116

VDMZ is our 6503 configured with private vlans.

some more of the config is this (and I do have a 6503 with an mscf daughter card):


interface Vlan116

description vendor-dmz public/private primary vlan

ip address secondary

ip address

ip access-group 140 in (this one has a permit any any at the end)

no ip redirects

no ip unreachables

private-vlan mapping 117-122

ip route


(where is address of router1)

I have a bgp peering with which is router2.

in router1 they can see the routes advertised via bgp and also in router2 they

can see the route for that I advertise to them via bgp.

I really appreciate your help,