Users Guide

Table Of Contents
Example: PVLAN deployment with L2-L3 boundary at the spine
layer
The following use case illustrates a deployment scenario in which the end devices that belong to different tenants are separated
using secondary VLANs. Here, the private VLAN domain is spanned across two data centers using an ISL trunk port. In this
example:
The configured trunk port carries the traffic for both the primary and secondary VLANs.
A router that is reachable through a promiscuous port provides L3 connectivity to the external network and between end
devices in the secondary VLANs.
Configuration notes
Only the primary VLANs are extended to the core L3 switch (spine).
On the leaf nodes, the primary VLAN port that is connected to the spine switch is the promiscuous port.
The spine switch is PVLAN agnostic. On the spine switch, the ports that connect to the leaf nodes AG1 and AG2 are normal
trunk ports in the respective VLANs.
Primary VLANs on the leaf nodes do not have an IP address. IP address is configured only on the spine switch, which is the
gateway for all hosts in the PVLAN domains. The spine switch performs the L3 IPv4 and IPv6 routing.
Layer 2 679