PVLAN Setup: True Statement | CCIE Security Exam | Cisco

PVLAN Setup

Prev Question Next Question

Question

Which statement about PVLAN setup is true?

Answers

Explanations

Click on the arrows to vote for the correct answer

A. B. C. D.

C.

PVLAN (Private VLAN) is a technology that allows an administrator to segment an Ethernet network by dividing it into smaller subnetworks, each with its own unique VLAN identifier (VLAN ID). Private VLANs help increase security by preventing direct communication between devices connected to the same VLAN.

In a typical VLAN, all ports connected to the same VLAN can communicate with each other, but in PVLAN, ports are divided into three types:

  1. Promiscuous Ports: These ports can communicate with all other ports, including community and isolated ports. They are typically connected to a router, firewall or other network gateway devices.

  2. Community Ports: These ports are assigned to a community VLAN and can communicate with other ports within the same community VLAN, including other community ports and the promiscuous port.

  3. Isolated Ports: These ports are assigned to an isolated VLAN and can only communicate with the promiscuous port, but not with other ports, including other isolated or community ports.

Now, let's go through the answer options one by one:

A. The host that is connected to the community port can communicate with a host that is connected to a different community port.

This statement is true. In PVLAN, hosts connected to different community ports within the same community VLAN can communicate with each other, but not with isolated ports or hosts connected to different community VLANs.

B. The host that is connected to the community port cannot communicate with hosts that are connected to the promiscuous port.

This statement is false. Hosts connected to community ports can communicate with the promiscuous port, as well as with other community ports within the same community VLAN.

C. The host that is connected to the community port cannot communicate with hosts that are connected to the isolated port.

This statement is false. Hosts connected to community ports can communicate with the promiscuous port and other community ports within the same community VLAN, but not with isolated ports.

D. The host that is connected to the community port can only communicate with hosts that are connected to the same community port.

This statement is false. Hosts connected to different community ports within the same community VLAN can communicate with each other.

Therefore, the correct answer is A: "The host that is connected to the community port can communicate with a host that is connected to a different community port."