2V0-621 · Question #149
An administrator creates a Private VLAN with a Primary VLAN ID of 2. The administrator than creates three Private VLANs as follows: Marketing PVLAN ID. 4 PVLAN Type. Isolated Accounting PVLAN ID. 5…
The correct answer is A. Change the PVLAN type for the Accounting network to Promiscuous. B. Change the PVLAN ID for the Accounting network to 2. Isolated secondary PVLANs can only communicate with promiscuous ports, so Accounting (Community) cannot reach Marketing (Isolated) under the current setup. The fix requires placing Accounting into a promiscuous role or the primary VLAN.
Question
An administrator creates a Private VLAN with a Primary VLAN ID of 2. The administrator than creates three Private VLANs as follows:
Marketing PVLAN ID. 4 PVLAN Type. Isolated Accounting PVLAN ID. 5 PVLAN Type. Community Secretary PVLAN ID. 17 PVLAN Type. Isolated Users in the Accounting PVLAN are reporting problems communicating with servers in the Marketing PVLAN. Which two actions could the administrator take to resolve this problem? (Choose two.)
Options
- AChange the PVLAN type for the Accounting network to Promiscuous.
- BChange the PVLAN ID for the Accounting network to 2.
- CChange the PVLAN type for Marketing network to Promiscuous.
- DChange the PVLAN ID for Accounting network to 4.
How the community answered
(17 responses)- A53% (9)
- C18% (3)
- D29% (5)
Why each option
Isolated secondary PVLANs can only communicate with promiscuous ports, so Accounting (Community) cannot reach Marketing (Isolated) under the current setup. The fix requires placing Accounting into a promiscuous role or the primary VLAN.
Changing the Accounting PVLAN type to Promiscuous allows those ports to communicate with all secondary PVLANs, including the isolated Marketing PVLAN, because promiscuous ports have unrestricted communication across all secondary VLANs within the same primary VLAN domain. This directly resolves the one-way isolation imposed by the Isolated PVLAN type on Marketing.
Assigning Accounting the Primary VLAN ID (2) places those ports into the primary VLAN domain, granting them promiscuous-level access that allows them to reach all secondary PVLANs including the isolated Marketing PVLAN. This achieves the same outcome as option A by repointing Accounting to the primary VLAN rather than a secondary one.
Changing Marketing to Promiscuous does not resolve the issue because community ports in Accounting are still restricted from initiating traffic to what were formerly isolated-type ports under PVLAN forwarding rules.
Moving Accounting's PVLAN ID to 4 places it in the same isolated PVLAN as Marketing, but isolated ports cannot communicate with each other regardless of sharing the same PVLAN ID - they can only reach promiscuous ports.
Concept tested: Private VLAN secondary type communication restrictions
Source: https://www.cisco.com/c/en/us/support/docs/switches/catalyst-6500-series-switches/10554-21.html
Topics
Community Discussion
No community discussion yet for this question.