IronPort Systems 4108GL Switch User Manual


 
14-36
Port-Based Virtual LANs (VLANs) and GVRP
GVRP
Port-Based Virtual LANs
(VLANs) and GVRP
As the preceeding table indicates, when you enable GVRP, a port that has a
Tagged or Untagged static VLAN has the option for both generating advertise-
ments and dynamically joining other VLANs.
Note In table 14-3, above, the Unknown VLAN parameters are configured on a per-
port basis using the CLI. The Tagged, Untagged, Auto, and Forbid options are
configured per static VLAN on every port, using either the menu interface or
the CLI.
Because dynamic VLANs operate as Tagged VLANs, and because a tagged port
on one device cannot communicate with an untagged port on another device,
HP recommends that you use Tagged VLANs for the static VLANs you will use
to generate advertisements.
GVRP and VLAN Access Control
When you enable GVRP on a switch, the default GVRP parameter settings
allow all of the switchs ports to transmit and receive dynamic VLAN adver-
tisements (GVRP advertisements) and to dynamically join VLANs. The two
preceding sections describe the per-port features you can use to control and
limit VLAN propagation. To summarize, you can:
Allow a port to advertise and/or join dynamic VLANs (Learn modethe
default).
Allow a port to send VLAN advertisements, but not receive them from
other devices; that is, the port cannot dynamically join a VLAN but other
devices can dynamically join the VLANs it advertises (Block mode).
Prevent a port from participating in GVRP operation (Disable mode).
Port-Leave From a Dynamic VLAN
A dynamic VLAN continues to exist on a port for as long as the port continues
to receive advertisements of that VLAN from another device connected to that
port or until you:
Convert the VLAN to a static VLAN (See Converting a Dynamic VLAN to
a Static VLAN on page 14-21.)
Reconfigure the port to Block or Disable
Disable GVRP
Reboot the switch
The time-to-live for dynamic VLANs is 10 seconds. That is, if a port has not
received an advertisement for an existing dynamic VLAN during the last 10
seconds, the port removes itself from that dynamic VLAN.