Thursday, February 4, 2010

Debian Mail Server Setup with Postfix + Dovecot + SASL + Squirrel Mail

Install Postfix MTA (Mail Transfer Agent)

Use the following command to install postfix in debian

#aptitude install postfix postfix-tls libsasl2 sasl2-bin libsasl2-modules popa3d

During installation, postfix will ask for few questions like name of server and answer those questions by entering your domain name and select Internet site for postfix.

Postfix configuration file is located at:/etc/postfix/main.cf. You can edit this file using popular text editor vi /etc/postfix/main.cf

Restart Postfix Server using the following command

#/etc/init.d/postfix restart

Install Dovecot

Dovecot is POP3/IMAP server which needs MTA like Postfix to work properly.

#aptitude install dovecot-imapd dovecot-pop3d dovecot-common

Dovecot configuration file is located at: /etc/dovecot/dovecot.conf

Before we proceed we need to make some changes with dovecot configuration file. Double check the following entries in the file if the values are entered properly.

Edit the dovecot configuration file using the following command

#vi /etc/dovecot/dovecot.conf

# specify protocols = imap imaps pop3 pop3s
protocols = pop3 imap
# uncomment this and change to no.
disable_plaintext_auth = no
pop3_uidl_format = %08Xu%08Xv

Now, create a user to test our pop3 mail with outlook:

#adduser user_name

Note: Always create a separate user to test your mail or ftp.

Restart Dovecot using the following command

#/etc/init.d/dovecot restart

Now, you can use your outlook express to test whether your new mail server is working or not. Just enter username: with password in outlook.

Remember you will NOT be able to send email outside your network, you will be only be able to send within your domain or local network. If you attempt to send email you get “relay access denied” error from outlook express. However, you should have no problems in receiving your email from outlook. Inorder to send email external email you will need to configure SASL authentication as described below.

Configure SASL Authentication with TLS

SASL Configuration + TLS (Simple authentication security layer with transport layer security) used mainly to authenticate users before sending email to external server, thus restricting relay access. If your relay server is kept open, then spammers could use your mail server to send spam. It is very essential to protect your mail server from misuse.

Let us set up SMTP authentication for our users with postfix and dovecot.

Edit the postfix configuration file /etc/postfix/main.cf and enter the few lines to enable authentication of our users

smtpd_sasl_auth_enable = yes
smtpd_sasl_local_domain = yourdomain.com
smtpd_recipient_restrictions = permit_mynetworks,permit_sasl_authenticated,reject_unauth_destination
smtpd_sasl_security_options = noanonymous

postfix does a chroot so it can’t communicate with saslauthd.

#rm -r /var/run/saslauthd/

#mkdir -p /var/spool/postfix/var/run/saslauthd

#ln -s /var/spool/postfix/var/run/saslauthd /var/run

#chgrp sasl /var/spool/postfix/var/run/saslauthd

#adduser postfix sasl

On the Dovecot side you also need to specify the dovecot authentication daemon socket. In this case we specify an absolute pathname. Refer to this postfix manual here

Edit /etc/dovecot/dovecot.conf file

#vi /etc/dovecot/dovecot.conf

Look for the line that starts with auth default, before that insert the lines below.

auth default {
mechanisms = plain login
passdb pam {
}
userdb passwd {
}
socket listen {
client {
path = /var/spool/postfix/private/auth
mode = 0660
user = postfix
group = postfix
}

}

}

Now, rename previous auth default to auth default2. If you dont rename this then dovecot server will give you error like multiple instances of auth default.

Now restart all the following components of mail server

#/etc/init.d/saslauthd restart

#/etc/init.d/postfix restart

#/etc/init.d/dovecot restart

Test whether your mail server works or not with your outlook express. Configure a user with a user name (without @domain) and make sure that you select my server requires authentication. Under settings select same as incoming mail server

Note:
1. If you dont enable My server requires authentication in outlook you cannot send emails to external recipients and you get relay access denied error.
2. Do not use root login to login to your mail server.
3. Dont forget to create a new user before you authenticate using outlook.

Forwarding Mails

Ever wondered how to forward your mails especially if you are a webmaster managing number of sites. You might need to forward any email sent to your primary email address. Its that easy. Just create a .forward file on your home directory. Insert list of emails addresses separated by commas, where you want to get forwarded.

Login as user and type

echo ‘destination_email_address’ > .forward

or you can use vi to create .forward file. Just Delete .forward file if you dont want any forwarding.

Installing Squirrel Web Mail

Before installing Squirrel Web Mail you need to make sure you have installed apache2 with php support

#aptitude install apache2

#aptitude install libapache2-mod-php5 php5-cli php5-common php5-cgi

#aptitude install squirrelmail

Squirrelmail configuration file is located in: /etc/squirrelmail/ folder. By default all settings are preloaded.

# Run squirrelmail configuration utility as ROOT
/usr/sbin/squirrelmail-configure

Now we want to setup to run under apache. Edit apache configuration file /etc/apache2/apache2.conf and insert the following line

Include /etc/squirrelmail/apache.conf

Restart the webserver using the following command

#/etc/init.d/apache2 restart

Access your webmail using the following link

http://yourdomain or server ip/squirrelmail

Create a separate local user and login as a new user.

Mail Server Logs

Always refer to logs located in /var/log/mail.log so that you can identify what the problem is before you can troubleshoot.

A detailed look at the filesystem in Debian

A typical Linux system has, among others, the following directories:

/

This is the root directory. This is where the whole tree starts.

/bin

This directory contains executable programs which are needed in single user mode and to bring the system up or repair it.

/boot

Contains static files for the boot loader. This directory only holds the files which are needed during the boot process.

/dev

Special or device files, which refer to physical devices.

/etc

Contains configuration files which are local to the machine. Some larger software packages, like X11, can have their own subdirectories below /etc. Site-wide configuration files may be placed here or in /usr/etc. Nevertheless, programs should always look for these files in /etc and you may have links for these files to /usr/etc.

/etc/skel

When a new user account is created, files from this directory are usually copied into the user's home directory.

/etc/X11

Configuration files for the X11 window system.

/home

On machines with home directories for users, these are usually beneath this directory, directly or not. The structure of this directory depends on local administration decisions.

/lib

This directory should hold those shared libraries that are necessary to boot the system and to run the commands in the root filesystem.

/mnt

is a mount point for temporarily mounted filesystems

/proc

This is a mount point for the proc filesystem, which provides information about running processes and the kernel.

/sbin

Like /bin, this directory holds commands needed to boot the system, but which are usually not executed by normal users.

/tmp

This directory contains temporary files which may be deleted with no notice, such as by a regular job or at system boot up.

/usr

This directory is usually mounted from a separate partition. It should hold only sharable, read-only data, so that it can be mounted by various machines running Linux.

/usr/X11R6

The X-Window system.

/usr/bin

This is the primary directory for executable pro grams. Most programs executed by normal users which are not needed for booting or for repairing the system and which are not installed locally should be placed in this directory.

/usr/bin/X11

is the traditional place to look for X11 executable's; on Linux, it usually is a symbolic link to /usr/X11R6/bin.

/usr/dict

This directory holds files containing word lists for spell checkers.

/usr/doc

You may find documentation about the installed software packages in this directory.

/usr/etc

Site-wide configuration files to be shared between several machines may be stored in this directory. However, commands should always reference those files using the /etc directory. Links from files in /etc should point to the appropriate files in /usr/etc.

/usr/include

Include files for the C compiler.

/usr/include/X11

Include files for the C compiler and the X-Windows system. This is usually a symbolic link to /usr/X11R6/include/X11.

/usr/include/asm

Include files which declare some assembler functions. This used to be a symbolic link to /usr/src/linux/include/asm.

/usr/include/linux

This contains information which may change from system release to system release and used to be a symbolic link to /usr/src/linux/include/linux to get at operating system specific information.

(Note that one should have include files there that work correctly with the current libc and in user space. However, Linux kernel source is not designed to be used with user programs and does not know anything about the libc you are using. It is very likely that things will break if you let /usr/include/asm and /usr/include/linux point at a random kernel tree. Debian systems don't do this and use headers from a known good kernel version, provided in the libc*-dev package.)

Include files to use with the GNU C++ compiler.

/usr/lib

Object libraries, including dynamic libraries, plus some executable's which usually are not invoked directly. More complicated programs may have whole subdirectories there.

/usr/lib/X11

The usual place for data files associated with X programs, and configuration files for the X system itself. On Linux, it usually is a symbolic link to /usr/X11R6/lib/X11

/usr/lib/gcc-lib

contains executable's and include files for the GNU C compiler.

/usr/lib/groff

Files for the GNU groff document formatting system.

/usr/local

This is where programs which are local to the site typically go.

/usr/local/bin

Binaries for programs local to the site go there.

/usr/local/doc

Local documentation

/usr/local/etc

Configuration files associated with locally installed programs go there.

/usr/local/lib

Files associated with locally installed programs go there.

/usr/local/info

Info pages associated with locally installed pro grams go there.

/usr/local/man

Manpages associated with locally installed programs go there.

/usr/local/sbin

Locally installed programs for system administration.

/usr/local/src

Source code for locally installed software.

/usr/man

Manpages traditionally go in there, into their sub directories.

/usr/sbin

This directory contains program binaries for system administration which are not essential for the boot process, for mounting /usr, or for system repair.

/usr/share

This directory contains subdirectories with specific application data, that can be shared among different architectures of the same OS. Often one finds stuff here that used to live in /usr/doc or /usr/lib or /usr/man.

/usr/share/man

Manpages go in there, into their subdirectories.

/usr/src

Source files for different parts of the system, included with some packages for reference purposes. Don't work here with your own projects, as files below /usr should be read-only except when installing software

/usr/src/linux

This has always been the traditional place where kernel sources were unpacked. This was important on systems that /usr/include/linux was a symlink here. You should probably use another directory for building the kernel now.

/usr/tmp

Obsolete. This should be a link to /var/tmp. This link is present only for compatibility reasons and shouldn't be used.

/var

This directory contains files which may change in size, such as spool and log files.

/var/adm

This directory is superseded by /var/log and should be a symbolic link to /var/log.

/var/backups

This directory is used to save backup copies of important system files.

/var/lock

Lock files are placed in this directory. The naming convention for device lock files is LCK.. where is the device's name in the filesystem. The format used is that of HDU UUCP lock files, i.e. lock files contain a PID as a 10-byte ASCII decimal number, followed by a newline character.

/var/log

Miscellaneous log files.

/var/preserve

This is where vi saves edit sessions so they can be restored later.

/var/run

Run-time variable files, like files holding process identifiers (PIDs) and logged user information (utmp). Files in this directory are usually cleared when the system boots.

/var/spool

Spooled (or queued) files for various programs.

/var/spool/at

Spooled jobs for at(1).

/var/spool/cron

Spooled jobs for cron

/var/spool/lpd

Spooled files for printing.

/var/spool/mail

Users' mailboxes.

/var/tmp

Like /tmp, this directory holds temporary files stored for an unspecified duration.

Sunday, January 10, 2010

Associate NCE Program (Network Consulting Engineer)

Advanced Services - Associate NCE Program (Network Consulting Engineer)

The aNCE (Associate Network Consulting Engineer) Program will provide a valuable, extensive and intense work experience - using the Cisco model of education, exposure and experience. First, education in a classroom environment - followed by exposure in a mentored environment - while you gain experience via hands on work. This is the Cisco EEE (Education/Exposure/Experience) learning framework. The end result is that you will be a trained and capable Network Consulting Engineer (NCE) as part of the Cisco Advanced Services (AS) team.

All participants will begin training at Cisco's RTP (Research Triangle Park, NC) facilities. Your final work location in the USA will be determined at a later date.

Phase I - is the first 3-4 months when you will spend 100% of your time training to acquire the technical experience (CCNA, CCNP & CCIE courses), trouble-shooting, process, professional and other skills to perform as a Cisco Associate Network Consulting Engineer (aNCE) in the new millennium. Professional skills include: teamwork, inter-personal, writing, presentation and consulting skills. It is expected that you will pass your CCNA and written CCIE examinations during this period. This is primarily an education (training) environment.

Phase II - a variable set of exposure and experience rotations for approximately 3 months. The set of rotations will be determined by your target position/organization in AS. You will work on complex and in-depth networking problems requiring strong analytical, problem solving, and engineering skills. This will be part exposure but mainly an experience (learning by doing) environment.

Phase III - This will be a rotation into a back-office Advanced Services support team to gain the exposure and experience in the world-class tools, process and people of the Advanced Services team. During this period you will receive education/exposure/experience in various technologies and AS processes. You will take the CCIE lab examination during this phase. This phase is targeted to last 4-6 weeks. This will be an Exposure (working with experts) environment.

Work Locations - You will be hired and must be willing to relocate to the Cisco campus in the Research Triangle Park (RTP), North Carolina for Phases I-III. Upon completion of all three phases, you will be relocated to meet Cisco business needs. Final work location will be determined after to joining and is based on the requirements of the Cisco AS delivery teams somewhere in the USA.

The Company - Discover all that's possible for your career!
Cisco Systems is one of the most innovative companies in the high-technology industry. We hire highly talented individuals who will contribute to Cisco’s global leadership in delivering networking products and solutions that help customers achieve their business goals.
Read more about working at Cisco and watch the video at:

http://www.cisco.com/web/about/ac40/about_cisco_careers_home.html


The Cisco Advanced Services team is a global organization charged with providing world class services to our customer base. Focused on premium customers, the AS team provides complex design, performance and optimization services to the largest networks in the world. Additionally, the AS team is in the vanguard of Advanced Technology implementation of Cisco leading edge technologies worldwide.

This is a fast paced, high impact environment where you will directly contribute to the success of Cisco's customers in deploying and utilizing the latest networking technologies. You will see a wide variety of real world customer networks and be constantly challenged to expand your networking knowledge, ability improve customer networks and to implement new services on the IP network infrastructure. You will become the Cisco expert that customers demand. See our website information on Advanced Services at:

http://www.cisco.com/en/US/products/svcs/ps11/services_segment_category_home.html

The Role
The Network Consulting Engineer (NCE) role is an ideal job for people who combine technical expertise, professional excellence and consulting skills.

The Cisco Advanced Services team works with the most advanced technologies and the best technical experts in the industry. At Cisco you will find the opportunity to do significant training because Cisco is the leader in Advanced and Emerging technologies (AT & ET). Advanced Services does the Plan-Design-Implement (PDI) and Optimize phases of these new technologies that will influence the human network. Be a part of the AS and Cisco team! The Advanced Services team is highly motivated and a place where people have a lot of fun doing their job.


Pre-Requisite:
US based candidates must already have a work authorization that permits them to work for Cisco indefinitely -- i.e., U.S. citizens, U.S. nationals, permanent residents, temporary residents (that is, individuals who have gone through the legalization program) refugees and asylees. Unfortunately, Cisco is not able to support any visa extensions, H-1B or other work permits for this program.

Eligibility Requirements:
Maximum of 2 years work experience and a new graduate, i.e. you have graduated within the last 24 months
3 to 4 year technical degree or a degree with demonstrated work experience in a technically related position
Technical degrees include Computer, Engineering, Sciences, Mathematics, etc.
Desirable but not required: Cisco Network Academy graduate

This position generally requires the following skills:

* Strong computer/network skills are desired but not required
* Strong ability to understand technical issues and apply technical concepts is required
* Passion for learning and demonstrated ability for independent study in addition to classroom instruction and team learning
* Ability to leverage technical expertise of others
* Exemplary written and verbal communication skills and ability to clearly communicate technical concepts
* Strong listening skills
* Ability to participate as a team member
* Ability to produce quality work under pressure with immediate deadlines
* Ability to take constructive feedback and make necessary changes
* Ability to give presentations to large or small groups
* Ability to adjust to a rapidly changing environment
* Ability to succeed in a highly unstructured environment


Responsibilities:
Develop solid knowledge of baseline Advanced Services (AS) skills
Develop knowledge as a Network Infrastructure (NI) specialist in core IP routing and switching
Attend and participate in technical and professional and in the first 3 months classes and events
Complete all projects and assignments on time
Highlights of the tasks to be completed within the first 3 months
Pass CCNA examination and take all CCNP examinations
Pass CCIE written certification exam
Successfully complete 3 formal presentations and join Toastmasters
Successfully complete 4 written assignments
Take the CCIE lab examination within the first 8 months
Pass the CCNP within the first 8 months
Additional certifications testing – CCDA & CCDP will be encouraged within the first 12 months

Long-term responsibilities (include but are not limited to)
Support delivery of service program to major accounts
Review network requirements and produce high and low level network designs
Review customer Implementation / Change Management Plans
Plan and execute complex Network Upgrade and Network Migration activity
Troubleshoot and resolve complex customer network problems across a broad range of technologies
Act as a technical focal point for large account network problem resolution
Attain the CCIE certification
Build simulated networks in test labs to resolve complex problems and compatibility issues
Generate reusable Intellectual Capital in the form of standard customer deliverables
Leverage and contribute to Virtual Teams
Question ways of working and suggest improvement

Monday, December 21, 2009

MPLS Topics

MPLS Concepts

* Introducing Basic MPLS Concepts
* Introducing MPLS Labels and Label Stacks
* Identifying MPLS Applications


Label Assignment and Distribution

* Discovering LDP Neighbors
* Introducing Typical Label Distribution in Frame-Mode MPLS
* Introducing Convergence in Frame-Mode MPLS
* Introducing MPLS Label Allocation, Distribution, and Retention Modes


Frame-Mode MPLS Implementation on Cisco IOS Platforms

* Introducing CEF Switching
* Configuring Frame-Mode MPLS on Cisco IOS Platforms
* Monitoring Frame-Mode MPLS on Cisco IOS Platforms
* Troubleshooting Frame-Mode MPLS on Cisco IOS Platforms


MPLS VPN Technology

* Introducing VPNs
* Categorizing VPNs
* Introducing MPLS VPN Architecture
* Introducing the MPLS VPN Routing Model
* Forwarding MPLS VPN Packets


MPLS VPN Implementation

* Using MPLS VPN Mechanisms on Cisco IOS Platforms
* Configuring VRF Tables
* Configuring an MP-BGP Session Between PE Routers
* Configuring Small-Scale Routing Protocols Between PE and CE Routers
* Monitoring MPLS VPN Operations
* Configuring OSPF as the Routing Protocol Between PE and CE routers
* Configuring BGP as the Routing Protocol Between PE and CE routers
* Troubleshooting MPLS VPNs


Complex MPLS VPNs

* Using Advanced VRF Import and Export Features
* Introducing Overlapping VPNs
* Introducing Central Services VPNs
* Introducing the Managed CE Routers Service


Internet Access and MPLS VPNs

* Introducing VPN Internet Access Topologies
* Implementing Separate Internet Access and VPN Services
* Implementing Internet Access as a Separate VPN


MPLS TE Overview

* Introducing the TE Concept
* Understanding MPLS TE Components
* Configuring MPLS TE on Cisco IOS Platforms
* Monitoring Basic MPLS TE on Cisco IOS Platforms

Monday, December 7, 2009

Private VLAN

To begin with, let’s recall that VLAN is essentially a broadcast domain. Private VLANs (PVANs) allow splitting the domain into multiple isolated broadcast “subdomains”, introducing subVLANs inside a VLAN. As we know, Ethernet VLANs can not communicate directly with each other – they require a L3 device to forward packets between separate broadcast domains. The same restriction applies to PVLANS – since the subdomains are isolated at Level 2, they need to communicate using an upper level (L3/packet forwarding) device – such as router. However, there is a difference here. In real life, different VLANs usually map to different IP subnets. When we split a VLAN using PVLANs, hosts in different PVLANs still belong to the same IP subnet, yet now they need to use a router (L3 device) to talk to each other (for example, by using local Proxy ARP). On its side, the router may either permit or forbid communications between sub-VLANs using access-lists. Commonly, these configurations arise in “shared” environments, say ISP co-location, where it’s beneficial to put multiple customers into the same IP subnet, yet provide a good level of isolation between them.

For our sample configuration, we will take VLAN 1000 and divide it into three PVLANs – sub-VLAN 1012 (R1 and R2), sub-VLAN 1034 (R3 and R4) and sub-VLAN 1055 (router R5 only). Router R6 will be used as layer 3 device, to resolve the layer 3 communication issue. Look at the figure above for reference. We define VLAN 1000 as “Primary” and classify the ports, assigned to this VLAN, based on their types:



Promiscuous (“P”) port: Usually connects to a router. This port type is allowed to send and receive L2 frames from any other port on the VLAN
Isolated (“I”) port: This type of port is only allowed to communicate with “P”-ports – i.e., they are “stub” port. You commonly see these ports connecting to hosts.
Community (“C”) port: Community ports are allowed to talk to their buddies, sharing the same community (group) and to “P”-ports.

In order to implement sub-VLAN behavior, we need to define how packets are forwarded between different types of ports. First comes the Primary VLAN – VLAN 1000 in our example. This type of VLANs is used to forward frames downstream from “P”-ports to all other port types (“I” and “C” ports) in the system. Essentially, Primary VLAN embraces all ports in the domain, but only transports frames from the router to hosts (from “P” to “I” and “C”). Next come “Secondary” VLANs – they correspond to “Isolated” and “Community” ports. These VLANs transport frames in the opposite direction (upstream) – from “I” and “C” ports to “P” ports.

Isolated VLAN: forwards frames from “I” ports to “P” ports. Since Isolated ports do not exchange frames with each other, we can use just ONE isolated VLAN to connect all I-Port to the P-port.
Community VLANs: Transport frames between community ports (C-ports) within to the same group (community) and forward frames upstream to the P-ports of the primary VLAN.

Here is a simplified overview of how Private VLANs work:

The Primary VLAN delivers frames downstream from the router (promisc port) to all mapped hosts; The Isolated VLAN transports frames from the stub hosts upstream to the router; The Community VLANs allow bi-directional frame exchange withing a single group, in addition to forwarding frames upstream towards “P”-ports. The original Ethernet MAC address learning and forwarding procedure remain the same, as well as broadcast/multicast flooding procedure within boundaries of primary/secondary VLANs. Naturally, private VLANs could be trunked. The secondary VLAN numbers are used to tag frames, just as with regular VLANs, and the primary VLAN traffic is trunked as well. However, you need to configure Private VLAN specific settings (bindings, mappings) on every participating swtich, for it’s not possible to use VTPv2 to dissiminate that information . This due to the fact that VTPv2 has no TLVs to carry private VLANs information, and besides, private VLANs are not intended to be floodes across the whole management domain. Not to mention that using VTP in enterprise networks is usually not a good idea. Though VTPv3 was designed to overcome this limitation among others.

Let’s move to the configuration part, based on the diagram above. What we have is primary VLAN 1000, Isolated VLAN 1005 (R5) Community VLAN 1012 (R1, R2) and Community VLAN 1034 (R3, R4).

Step 1:

First, disable VTP, i.e. enable VTP transparent mode. After disabling VTP, create Primary and Secondary VLANs and bind them into PVLAN domain:

SW1:
vtp mode transparent
!
! Creating primary VLAN, which is shared among secondary’s
!
vlan 1000
private-vlan primary

!
! Community VLAN for R1 and R2: allows a “subVLAN” within a Primary VLAN
!
vlan 1012
private-vlan community
!
! Community VLAN for R3 and R4
!
vlan 1034
private-vlan community

!
! Isolated VLAN: Connects all stub hosts to router.
! Remember - only one isolated vlan per primary VLAN.
! In our case, isolates R5 only.
!
vlan 1055
private-vlan isolated

!
! Associating the primary with secondary’s
!
vlan 1000
private-vlan association 1012,1034,1055

This step is needed is to group PVLANs into a shared domain and establish a formal association (for syntax checking and VLAN type verifications). Repeat the same operations on SW2, since VTP has been disabled.

Step 2:

Configure host ports and bind them to the respective isolated PVLANs. Note that a host port belongs to different VLANs at the same time: downstream primary and upstream secondary. Also, enable trunking between switches, to allow private VLANs traffic to pass between switches.

SW1:
!
! Community port (links R1 to R2 and “P”-ports)
!
interface FastEthernet0/1
description == R1
switchport private-vlan host-association 1000 1012
switchport mode private-vlan host
spanning-tree portfast

!
! Community port (links R3 to R4 and “P”-ports)
!
interface FastEthernet0/3
description == R3
switchport private-vlan host-association 1000 1034
switchport mode private-vlan host
spanning-tree portfast

!
! Isolated port (uses isolated VLAN to talk to “P”-ports)
!
interface FastEthernet0/5
description == R5
switchport private-vlan host-association 1000 1055
switchport mode private-vlan host
spanning-tree portfast

!
! Trunk port
!
interface FastEthernet 0/13
switchport trunk encapsulation dot1q
switchport mode trunk

SW2:
interface FastEthernet0/2
description == R2
switchport private-vlan host-association 1000 1012
switchport mode private-vlan host
spanning-tree portfast
!
interface FastEthernet0/4
description == R4
switchport private-vlan host-association 1000 1034
switchport mode private-vlan host
spanning-tree portfast

!
! Trunk port
!
interface FastEthernet 0/13
switchport trunk encapsulation dot1q
switchport mode trunk

Next, Verify the configuration on SW1:

Rack1SW1#show vlan id 1012

VLAN Name Status Ports
---- -------------------------------- --------- -------------------------------
1012 VLAN1012 active Fa0/13

VLAN Type SAID MTU Parent RingNo BridgeNo Stp BrdgMode Trans1 Trans2
---- ----- ---------- ----- ------ ------ -------- ---- -------- ------ ------
1012 enet 101012 1500 - - - - - 0 0

Remote SPAN VLAN
----------------
Disabled

Primary Secondary Type Ports
------- --------- ----------------- ------------------------------------------
1000 1012 community Fa0/1

Rack1SW1#show vlan id 1034

VLAN Name Status Ports
---- -------------------------------- --------- -------------------------------
1034 VLAN1034 active Fa0/13

VLAN Type SAID MTU Parent RingNo BridgeNo Stp BrdgMode Trans1 Trans2
---- ----- ---------- ----- ------ ------ -------- ---- -------- ------ ------
1034 enet 101034 1500 - - - - - 0 0

Remote SPAN VLAN
----------------
Disabled

Primary Secondary Type Ports
------- --------- ----------------- ------------------------------------------
1000 1034 community Fa0/3

Rack1SW1#show vlan id 1055

VLAN Name Status Ports
---- -------------------------------- --------- -------------------------------
1055 VLAN1055 active Fa0/13

VLAN Type SAID MTU Parent RingNo BridgeNo Stp BrdgMode Trans1 Trans2
---- ----- ---------- ----- ------ ------ -------- ---- -------- ------ ------
1055 enet 101055 1500 - - - - - 0 0

Remote SPAN VLAN
----------------
Disabled

Primary Secondary Type Ports
------- --------- ----------------- ------------------------------------------
1000 1055 isolated Fa0/5

Rack1SW1#show interfaces fastEthernet 0/13 trunk

Port Mode Encapsulation Status Native vlan
Fa0/13 desirable 802.1q trunking 1

Port Vlans allowed on trunk
Fa0/13 1-4094

Port Vlans allowed and active in management domain
Fa0/13 1,1000,1012,1034,1055

Port Vlans in spanning tree forwarding state and not pruned
Fa0/13 1,1000,1012,1034,1055

Verify on SW2:

Rack1SW2#show vlan id 1000

VLAN Name Status Ports
---- -------------------------------- --------- -------------------------------
1000 VLAN1000 active Fa0/13

VLAN Type SAID MTU Parent RingNo BridgeNo Stp BrdgMode Trans1 Trans2
---- ----- ---------- ----- ------ ------ -------- ---- -------- ------ ------
1000 enet 101000 1500 - - - - - 0 0

Remote SPAN VLAN
----------------
Disabled

Primary Secondary Type Ports
------- --------- ----------------- ------------------------------------------
1000 1012 community Fa0/2, Fa0/6
1000 1034 community Fa0/4, Fa0/6
1000 1055 isolated Fa0/6

Rack1SW2#show vlan id 1012

VLAN Name Status Ports
---- -------------------------------- --------- -------------------------------
1012 VLAN1012 active Fa0/13

VLAN Type SAID MTU Parent RingNo BridgeNo Stp BrdgMode Trans1 Trans2
---- ----- ---------- ----- ------ ------ -------- ---- -------- ------ ------
1012 enet 101012 1500 - - - - - 0 0

Remote SPAN VLAN
----------------
Disabled

Primary Secondary Type Ports
------- --------- ----------------- ------------------------------------------
1000 1012 community Fa0/2, Fa0/6

Rack1SW2#show vlan id 1034

VLAN Name Status Ports
---- -------------------------------- --------- -------------------------------
1034 VLAN1034 active Fa0/13

VLAN Type SAID MTU Parent RingNo BridgeNo Stp BrdgMode Trans1 Trans2
---- ----- ---------- ----- ------ ------ -------- ---- -------- ------ ------
1034 enet 101034 1500 - - - - - 0 0

Remote SPAN VLAN
----------------
Disabled

Primary Secondary Type Ports
------- --------- ----------------- ------------------------------------------
1000 1034 community Fa0/4, Fa0/6

Rack1SW2#show vlan id 1055


VLAN Name Status Ports
---- -------------------------------- --------- -------------------------------
1055 VLAN1055 active Fa0/13

VLAN Type SAID MTU Parent RingNo BridgeNo Stp BrdgMode Trans1 Trans2
---- ----- ---------- ----- ------ ------ -------- ---- -------- ------ ------
1055 enet 101055 1500 - - - - - 0 0

Remote SPAN VLAN
----------------
Disabled

Primary Secondary Type Ports
------- --------- ----------------- ------------------------------------------
1000 1055 isolated Fa0/6

Rack1SW2#show interface fastEthernet 0/13 trunk

Port Mode Encapsulation Status Native vlan
Fa0/13 desirable 802.1q trunking 1

Port Vlans allowed on trunk
Fa0/13 1-4094

Port Vlans allowed and active in management domain
Fa0/13 1,1000,1012,1034,1055

Port Vlans in spanning tree forwarding state and not pruned
Fa0/13 1,1000,1012,1034,1055

Step 3:

Create a promiscuous port and configure downstream mappings. Here we add secondary VLANs for which traffic is received by this particular “P”-port. Primary VLAN is used to send traffic downstream to all “C” and “I” ports per their associations.

SW2:
!
! Promiscuous port, mapped to all secondary VLANs
!
interface FastEthernet0/6
description == R6
switchport private-vlan mapping 1000 1012,1034,1055
switchport mode private-vlan promiscuous
spanning-tree portfast

Verify the promiscuous port configuration:

Rack1SW2#show int fa 0/6 switch | beg private

Administrative Mode: private-vlan promiscuous
Operational Mode: private-vlan promiscuous
Administrative Trunking Encapsulation: negotiate
Operational Trunking Encapsulation: native
Negotiation of Trunking: Off
Access Mode VLAN: 1 (default)
Trunking Native Mode VLAN: 1 (default)
Administrative Native VLAN tagging: enabled
Voice VLAN: none
Administrative private-vlan host-association: none
Administrative private-vlan mapping: 1000 (VLAN1000) 1012 (VLAN1012) 1034 (VLAN1034) 1055 (VLAN1055)
Administrative private-vlan trunk native VLAN: none
Administrative private-vlan trunk Native VLAN tagging: enabled
Administrative private-vlan trunk encapsulation: dot1q
Administrative private-vlan trunk normal VLANs: none
Administrative private-vlan trunk private VLANs: none
Operational private-vlan:
1000 (VLAN1000) 1012 (VLAN1012) 1034 (VLAN1034) 1055 (VLAN1055)

If you need to configure an SVI on a switch to communicate with private VLAN members, you should add an interface corresponding to Primary VLAN only. Obviously that’s because all secondary VLANs are “subordinates” of primary. After an SVI has been created, you have to map the required secondary VLANs to the SVI (just like with a promiscuous port) in order to make communications possible. You may exclude some mappings from SVI interface, and limit it to communicating only with certain secondary VLANs.

SW1:
!
! SW1 SVI is mapped to all secondary VLANs
!
interface Vlan 1000
ip address 10.0.0.7 255.255.255.0
private-vlan mapping 1012,1034,1055

SW2:
!
! SW2 SVI is mapped to 1012/1034 only, so it’s cant communicate with R5
!
interface Vlan1000
ip address 10.0.0.8 255.255.255.0
private-vlan mapping 1012,1034

Now to verify the configuration, configure R1-R6 interfaces in subnet “10.0.0.0/24” and ping broadcast addresses.

Rack1R1#ping 10.0.0.255 repeat 1

Type escape sequence to abort.
Sending 1, 100-byte ICMP Echos to 10.0.0.255, timeout is 2 seconds:

Reply to request 0 from 10.0.0.7, 4 ms
Reply to request 0 from 10.0.0.2, 4 ms
Reply to request 0 from 10.0.0.6, 4 ms
Reply to request 0 from 10.0.0.8, 4 ms

Rack1R3#ping 10.0.0.255 repeat 1

Type escape sequence to abort.
Sending 1, 100-byte ICMP Echos to 10.0.0.255, timeout is 2 seconds:

Reply to request 0 from 10.0.0.7, 4 ms
Reply to request 0 from 10.0.0.4, 4 ms
Reply to request 0 from 10.0.0.6, 4 ms
Reply to request 0 from 10.0.0.8, 4 ms

Rack1R5#ping 10.0.0.255 repeat 1

Type escape sequence to abort.
Sending 1, 100-byte ICMP Echos to 10.0.0.255, timeout is 2 seconds:

Reply to request 0 from 10.0.0.7, 1 ms
Reply to request 0 from 10.0.0.6, 1 ms

Rack1R6#ping 10.0.0.255 repeat 1

Type escape sequence to abort.
Sending 1, 100-byte ICMP Echos to 10.0.0.255, timeout is 2 seconds:

Reply to request 0 from 10.0.0.1, 4 ms
Reply to request 0 from 10.0.0.7, 4 ms
Reply to request 0 from 10.0.0.2, 4 ms
Reply to request 0 from 10.0.0.5, 4 ms
Reply to request 0 from 10.0.0.3, 4 ms
Reply to request 0 from 10.0.0.4, 4 ms
Reply to request 0 from 10.0.0.8, 4 ms

Lastly, there is another feature, called protected port or “Private VLAN edge”. The feature is pretty basic and is available even on low-end Cisco switches. It allows isolating ports in the same VLAN. Specifically, all ports in a VLAN, marked as protected are prohibited from sending frames to each other (but still allowed to send frames to other (non-protected) ports within the same VLAN). Usually, ports configured as protected are also configured not to receive unknown unicast (frame with destination MAC address not in switch’s MAC table) and multicast frames flooding for added security.

Example:

interface range FastEthernet 0/1 - 2
switchport mode access
switchport protected
switchport block unicast
switchport block multicast